Audit Open Original ↗
Wikimedia Foundation OATHAuth MediaWiki Module
Type
Security review
Client
The Wikimedia Foundation
Date
2026-08
Domain
AppSec
Effort
4.6 wks
Section
Technology Product Reviews
Trail of Bits's security review of The Wikimedia Foundation (Aug 2026) identified 33 issues: 2 high, 9 medium, 6 low, and 16 informational.
Findings · 33
- 1 Recovery codes with attached data are stored in plaintext Informational
- 2 Nonce reuse in recovery code encryption Low
- 3 Plaintext secrets are accepted when at-rest encryption is enabled Medium
- 4 Encrypted 2FA secrets can be swapped between users Medium
- 5 Lenient Base32 decoding in dependency christian-riesen/base32 Informational
- 6 The jakobo/hotp-php library does not fully implement RFC 6238 Informational
- 7 The DisableOATHForUser special page does not enforce sitewide blocks Medium
- 8 WikiText markup can be injected on the OATHManage special page Informational
- 9 TOTP resistance decreases with the number of registered authenticators Medium
- 10 Missing CSRF token on ApiQueryOATH can enable XS-Leaks on other user’s 2FA status Low
- 11 The disableoath rate limit counter is never incremented Low
- 12 Obsolete ApiOATHValidate endpoint exposes a TOTP validation oracle Informational
- 13 Incomplete notifications and logging for security-sensitive 2FA operations Informational
- 14 TOTP enrollment secret persists in session for full session lifetime Informational
- 15 Unbounded recovery code generation via Recover2FAForUser Informational
- 16 TOCTOU window on the badoath rate limiter allows extra verification attempts Medium
- 17 CredentialForm.getErrorText falls back to rendering raw strings as HTML Informational
- 18 Disable action bypasses mandatory 2FA enforcement, allowing downgrade to recovery codes only Informational
- 19 Unbounded resource consumption in spomky-labs/cbor-php High
- 20 Passkey registration mode is client-controlled and unenforced server-side Informational
- 21 Deprecated SHA-1 algorithm accepted for WebAuthn ceremonies Informational
- 22 No minimum RSA key size enforced for WebAuthn credentials Medium
- 23 WebAuthn origin validation ignores the port component Informational
- 24 WebAuthn challenges are valid for 24 hours Informational
- 25 WebAuthn credential ID is not checked for cross-user uniqueness Low
- 26 TOTP rate limiting and replay protection fail open when there is no persistent cache backend and during outages Medium
- 27 Bot password sessions bypass reauthentication for credential changes High
- 28 Disabling 2FA does not require proof of the second factor Medium
- 29 WebAuthn sign counter is never persisted after authentication Low
- 30 2FA session flag persists after 2FA is disabled Medium
- 31 Recovery code verification and consumption are not atomic Low
- 32 SecuritySensitiveOperationStatus hook can downgrade reauthentication requirements Informational
- 33 WebAuthn API endpoints disclose credential metadata without reauthentication Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related