PT-2020-7503 · Mediawiki+1 · Mediawiki Centralnotice Extension+1

Mark Bergsma

+1

·

Published

2013-12-12

·

Updated

2020-02-10

·

CVE-2013-4572

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: MediaWiki CentralNotice extension versions 1.19.x through 1.19.8 MediaWiki CentralNotice extension versions 1.20.x through 1.20.7 MediaWiki CentralNotice extension versions 1.21.x through 1.21.2
Description: The issue allows remote attackers to authenticate as a created user due to the Cache-Control header setting to cache session cookies when a user is autocreated.
Recommendations: For versions 1.19.x through 1.19.8, update to version 1.19.9 or later. For versions 1.20.x through 1.20.7, update to version 1.20.8 or later. For versions 1.21.x through 1.21.2, update to version 1.21.3 or later.

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1172
CVE-2013-4572
DSA-2891-1
MGASA-2013-0368

Affected Products

Alt Linux
Mediawiki Centralnotice Extension