Description
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site level. Thus, multiple requests can be made across many wikis/sites concurrently.
Remediation
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-0800)
WordPress Plugin Cross-RSS Directory Traversal (1.7)
WordPress Plugin W3 Total Cache Information Disclosure (0.9.2.4)
Joomla! Core 3.x.x Open Redirect (3.0.0 - 3.9.20)
Apache Tomcat 7PK - Security Features Vulnerability (CVE-2014-9634)