Impact
A session fixation flaw in Wikimedia Foundation OAuth allows an attacker to supply a chosen session identifier before the authentication process and have it accepted. This flaw permits wrongful access to a victim's authenticated session, effectively hijacking it. The vulnerability is classified as CWE‑384 because the system fails to reset or regenerate session states upon successful authentication.
Affected Systems
All releases of Wikimedia Foundation OAuth up to and including version 1.46.0, as well as the separately listed releases 1.45.4, 1.44.6, and 1.43.9, are impacted. Deployment of any of these versions for authentication or authorization exposes the system to the session fixation risk.
Risk and Exploitability
The EPSS score is < 1%, indicating a non‑zero but very low likelihood of exploitation, and the vulnerability is not recorded in the CISA KEV catalog. It is inferred that an attacker would trigger the flaw by presenting a crafted session token during the OAuth handshake; the server would accept it and the attacker could subsequently use that session to access protected resources as the victim.
OpenCVE Enrichment