PT-2023-25673 · Mediawiki+1 · Mediawiki+1

Arlolra

·

Published

2023-07-05

·

Updated

2024-10-08

·

CVE-2023-36674

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.35.11 MediaWiki versions 1.36.x through 1.38.x before 1.38.7 MediaWiki versions 1.39.x before 1.39.4 MediaWiki versions 1.40.x before 1.40.1
Description An issue was discovered in MediaWiki. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax.
Recommendations For versions prior to 1.35.11, update to version 1.35.11 or later. For versions 1.36.x through 1.38.x before 1.38.7, update to version 1.38.7 or later. For versions 1.39.x before 1.39.4, update to version 1.39.4 or later. For versions 1.40.x before 1.40.1, update to version 1.40.1 or later. As a temporary workaround, consider restricting the use of the thumb parameter in the File syntax until a patch is available.

Fix

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4877
ALT-PU-2023-6419
ALT-PU-2024-11168
ALT-PU-2024-1228
BIT-MEDIAWIKI-2023-36674
CVE-2023-36674
DSA-5447-1
MGASA-2023-0241

Affected Products

Alt Linux
Mediawiki