CVE-2021-45038
Published: 17 December 2021
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.
Priority
CVSS 3 base score: 5.3
Status
Package | Release | Status |
---|---|---|
mediawiki Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(code not present)
|
focal |
Not vulnerable
(code not present)
|
|
hirsute |
Ignored
(reached end-of-life)
|
|
impish |
Needed
|
|
jammy |
Not vulnerable
(1:1.35.5-1)
|
|
trusty |
Not vulnerable
(code not present)
|
|
upstream |
Released
(1:1.35.5-1)
|
|
xenial |
Does not exist
|
Notes
Author | Note |
---|---|
sbeattie | include upstream dda5355c0ee804c94ff371a8a16c4a2a8e4436bd as a prerequisite to the fix for this CVE to make it apply more cleanly. introduced in 0a8403271109 (v1.33.0) |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45038
- https://phabricator.wikimedia.org/T297574
- https://lists.wikimedia.org/hyperkitty/list/wikitech-l@lists.wikimedia.org/thread/QEN3EK4JXAVJMJ5GF3GYOAKNJPEKFQYA/
- NVD
- Launchpad
- Debian