PT-2021-19920 · Mediawiki · Datadump

Redmin

·

Published

2021-07-20

·

Updated

2021-07-28

·

CVE-2021-32774

CVSS v3.1

6.1

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DataDump versions prior to commit 67a82b76e186925330b89ace9c5fd893a300830b
Description The issue concerns a lack of protection against CSRF attacks in the DataDump MediaWiki extension, allowing forged requests to generate or delete dumps. There are no known workarounds.
Recommendations For versions prior to commit 67a82b76e186925330b89ace9c5fd893a300830b, completely disable DataDump as there is no other known mitigation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32774
GHSA-29MH-4VHV-X8MR

Affected Products

Datadump