PT-2021-3348 · Mediawiki+1 · Mediawiki+1

Magiczocker10

·

Published

2021-04-09

·

Updated

2024-03-06

·

CVE-2021-30152

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions 1.31.13 and earlier MediaWiki versions 1.32.x through 1.35.1
Description An issue was discovered in MediaWiki related to the "protect" page function via the MediaWiki API. This issue allows a user to protect a page to a higher level than their current permissions. The problem is associated with inadequate access control, which could allow a remote attacker to impact the integrity of protected information.
Recommendations For MediaWiki versions 1.31.13 and earlier, update to version 1.31.13 or later. For MediaWiki versions 1.32.x through 1.35.1, update to version 1.35.2 or later. As a temporary workaround, consider restricting access to the MediaWiki API "protect" page function until a patch is available.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1712
ALT-PU-2021-2091
BDU:2021-03165
BIT-MEDIAWIKI-2021-30152
CVE-2021-30152
DLA-2648-1
DLA-2648-2
DSA-4889-1
MGASA-2021-0218

Affected Products

Alt Linux
Mediawiki