Alerts This Week
Warning Icon 1 770
Alerts This Week
Warning Icon 1 770

Fedora 37: FEDORA-2023-30a7a812f0 Critical MediaWiki Threats and Fixes

fedora
Calendar Grey January 27, 2023
Dist Fedora Esm H88
An update to MediaWiki has been rolled out on Fedora 37, focusing on mitigating serious security vulnerabilities such as Cross-Site Scripting (XSS) and Denial of Service (DoS) risks.
https://www.mediawiki.org/wiki/Release_notes/1.38 https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/UEMW64LVEH3BEXCJV43CVS6XPYURKWU3/

Summary

MediaWiki is the software used for Wikipedia and the other Wikimedia

Foundation websites. Compared to other wikis, it has an excellent

range of features and support for high-traffic websites using multiple

servers

This package supports wiki farms. Read the instructions for creating wiki

instances under /usr/share/doc/mediawiki/README.RPM.

Remember to remove the config dir after completing the configuration.

https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/UEMW64LVEH3BEXCJV43CVS6XPYURKWU3/

* Wed Jan 18 2023 Michael Cronenworth - 1.38.5-1

- Update to 1.38.5

[ 1 ] Bug #2156317 - CVE-2021-44854 mediawiki: Rest API incorrectly publicly caches results from private wikis [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2156317

[ 2 ] Bug #2156319 - CVE-2021-44855 mediawiki: Blind Stored XSS via Upload Image via URL [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2156319

[ 3 ] Bug #2156327 - CVE-2021-44856 mediawiki: Title blocked in AbuseFilter can be created via Special:ChangeContentModel due to the mishandling of EditFilterMergedContent hook return value [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2156327

[ 4 ] Bug #2156330 - CVE-2022-41765 mediawiki: HTMLUserTextField exposes existence of hidden users [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2156330

[ 5 ] Bug #2156332 - CVE-2022-41767 mediawiki: reassignEdits doesn't update results in an IP range check on Special:Contributions [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2156332

[ 6 ] Bug #2160626 - CVE-2022-47927 mediawiki: sqlite information leak [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2160626

[ 7 ] Bug #2161176 - CVE-2023-22945 mediawiki: GrowthExperiments growthmanagementorlist API allows blocked users to enroll as mentors [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2161176

[ 8 ] Bug #2161180 - CVE-2023-22911 mediawiki: XSS in widget placement [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2161180

[ 9 ] Bug #2161187 - CVE-2023-22909 mediawiki: Remote DoS [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2161187

su -c 'dnf upgrade --advisory FEDORA-2023-30a7a812f0' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 37
Version: 1.38.5
Release: 1.fc37
Summary: A wiki engine

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here