PT-2021-11622 · Mediawiki+1 · Push Extension+2

Tosfos

·

Published

2020-10-10

·

Updated

2024-03-06

·

CVE-2020-29005

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: MediaWiki versions through 1.35
Description: The issue concerns the API in the Push extension for MediaWiki, which used cleartext for ApiPush credentials. This could potentially lead to information disclosure.
Recommendations: For MediaWiki versions through 1.35, consider disabling the Push extension until a secure version is available to prevent potential information disclosure. Restrict access to the API endpoints related to the Push extension to minimize the risk of exploitation. Avoid using cleartext credentials in the ApiPush configuration until the issue is resolved.

Fix

Cleartext Transmission of Sensitive Information

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3022
ALT-PU-2020-3055
BIT-MEDIAWIKI-2020-29005
CVE-2020-29005

Affected Products

Alt Linux
Mediawiki
Push Extension