PT-2020-16728 · Mediawiki+1 · Mediawiki+1

Risker

·

Published

2020-10-22

·

Updated

2024-03-06

·

CVE-2020-27621

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.35.0
Description The issue concerns the FileImporter extension, which failed to properly attribute user actions to a specific user's IP address. It would report the IP address of an internal server instead, by omitting X-Forwarded-For data, resulting in an inability to properly audit and attribute user actions performed via the FileImporter extension.
Recommendations For versions prior to 1.35.0, update to version 1.35.0 or later to resolve the issue.

Exploit

Fix

Related Identifiers

ALT-PU-2020-3554
ALT-PU-2020-3568
BIT-MEDIAWIKI-2020-27621
CVE-2020-27621

Affected Products

Alt Linux
Mediawiki