------------------------------------------------------------------------- Debian LTS Advisory DLA-3540-1 [email protected] https://www.debian.org/lts/security/ Markus Koschany August 23, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : mediawiki Version : 1:1.31.16-1+deb10u6 CVE ID : CVE-2023-29141 An auto-block can occur for an untrusted X-Forwarded-For header in MediaWiki, a website engine for collaborative work. X-Forwarded-For is not necessarily trustworthy and can specify multiple IP addresses in a single header, all of which are checked for blocks. When a user is autoblocked, the wiki will create an IP block behind-the-scenes for that user without exposing the user's IP on-wiki. However, spoofing XFF would let an attacker guess at the IPs of users who have active autoblocks, since the block message includes the username of the original block target. For Debian 10 buster, this problem has been fixed in version 1:1.31.16-1+deb10u6. We recommend that you upgrade your mediawiki packages. For the detailed security status of mediawiki please refer to its security tracker page at: https://security-tracker.debian.org/tracker/mediawiki Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS