{
  "modified": "2025-08-09T19:01:29Z",
  "published": "2020-02-08T18:15:11Z",
  "id": "CVE-2012-4381",
  "details": "MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.",
  "severity": [
    {
      "type": "CVSS_V3",
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://www.openwall.com/lists/oss-security/2012/08/31/10"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.openwall.com/lists/oss-security/2012/08/31/6"
    },
    {
      "type": "ADVISORY",
      "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=686330"
    },
    {
      "type": "ADVISORY",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=853442"
    },
    {
      "type": "ADVISORY",
      "url": "https://lists.wikimedia.org/pipermail/mediawiki-announce/2012-August/000119.html"
    },
    {
      "type": "ADVISORY",
      "url": "https://phabricator.wikimedia.org/T41184"
    },
    {
      "type": "ARTICLE",
      "url": "http://www.openwall.com/lists/oss-security/2012/08/31/10"
    },
    {
      "type": "ARTICLE",
      "url": "http://www.openwall.com/lists/oss-security/2012/08/31/6"
    },
    {
      "type": "ARTICLE",
      "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=686330"
    },
    {
      "type": "FIX",
      "url": "http://www.openwall.com/lists/oss-security/2012/08/31/10"
    },
    {
      "type": "FIX",
      "url": "http://www.openwall.com/lists/oss-security/2012/08/31/6"
    },
    {
      "type": "FIX",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=853442"
    },
    {
      "type": "FIX",
      "url": "https://lists.wikimedia.org/pipermail/mediawiki-announce/2012-August/000119.html"
    },
    {
      "type": "FIX",
      "url": "https://phabricator.wikimedia.org/T41184"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=853442"
    },
    {
      "type": "WEB",
      "url": "http://osvdb.org/show/osvdb/85106"
    }
  ]
}
