CVE-2016-2041
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restrictions by measuring time differences.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.65% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- fedoraproject/fedora · phpmyadmin/phpmyadmin · opensuse/leap · opensuse/opensuse
- Source
- cve@mitre.org
References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176483.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176739.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00028.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00049.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3627
- http://www.phpmyadmin.net/home_page/security/PMASA-2016-5.phpPatch, Vendor Advisory
- https://github.com/phpmyadmin/phpmyadmin/commit/ec0e88e37ef30a66eada1c072953f4ec385a3e49Patch
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176483.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176739.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00028.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00049.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3627
- http://www.phpmyadmin.net/home_page/security/PMASA-2016-5.phpPatch, Vendor Advisory
- https://github.com/phpmyadmin/phpmyadmin/commit/ec0e88e37ef30a66eada1c072953f4ec385a3e49Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.