PT-2020-16250 · Wikimedia+1 · Mediawiki+1

Martin Urbanec

+1

·

Published

2020-09-27

·

Updated

2024-03-06

·

CVE-2020-25869

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.31.10 MediaWiki versions 1.32.x through 1.34.3
Description An information leak was discovered due to incorrect handling of actor ID, which may not use the correct database or wiki.
Recommendations For MediaWiki versions prior to 1.31.10, update to version 1.31.10 or later. For MediaWiki versions 1.32.x through 1.34.3, update to version 1.34.4 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3022
ALT-PU-2020-3055
BIT-MEDIAWIKI-2020-25869
CVE-2020-25869
MGASA-2020-0381

Affected Products

Alt Linux
Mediawiki