PT-2021-24162 · Mediawiki+1 · Mediawiki+1
Dylsss
·
Published
2021-12-15
·
Updated
2024-03-06
·
CVE-2021-44858
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
MediaWiki versions prior to 1.35.5
MediaWiki versions 1.36.x prior to 1.36.3
MediaWiki versions 1.37.x prior to 1.37.1
Description:
An issue allows viewing private pages on a private wiki with at least one page set in
$wgWhitelistRead by using specific actions in sequence, such as action=edit&undo= followed by action=mcrundo and action=mcrrestore.Recommendations:
For MediaWiki versions prior to 1.35.5, update to version 1.35.5 or later.
For MediaWiki versions 1.36.x prior to 1.36.3, update to version 1.36.3 or later.
For MediaWiki versions 1.37.x prior to 1.37.1, update to version 1.37.1 or later.
As a temporary workaround, consider restricting access to the
action=mcrundo and action=mcrrestore endpoints to minimize the risk of exploitation.Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Mediawiki