PT-2021-6527 · Mediawiki+1 · Mediawiki+1

Legoktm

·

Published

2021-06-27

·

Updated

2024-03-06

·

CVE-2021-35197

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions 1.31.15 and earlier MediaWiki versions 1.32.x through 1.35.x before 1.35.3 MediaWiki versions 1.36.x before 1.36.1
Description The issue concerns unintended API access for bots in MediaWiki. When a bot account has a "sitewide block" applied, it can still "purge" pages through the MediaWiki Action API, which should have been prevented by the block. This could potentially allow a remote attacker to impact data integrity.
Recommendations For MediaWiki versions 1.31.15 and earlier, update to version 1.31.15 or later. For MediaWiki versions 1.32.x through 1.35.x before 1.35.3, update to version 1.35.3 or later. For MediaWiki versions 1.36.x before 1.36.1, update to version 1.36.1 or later. As a temporary workaround, consider restricting access to the MediaWiki Action API for bot accounts with a "sitewide block" applied.

Exploit

Fix

Incorrect Authorization

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2064
ALT-PU-2021-2091
BDU:2022-01787
BIT-MEDIAWIKI-2021-35197
CVE-2021-35197
DLA-2779-1
DSA-4979-1
MGASA-2021-0346

Affected Products

Alt Linux
Mediawiki