MGASA-2020-0381 - Updated mediawiki packages fix security vulnerability

Publication date: 30 Sep 2020
URL: https://advisories.mageia.org/MGASA-2020-0381.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2020-25812,
     CVE-2020-25813,
     CVE-2020-25814,
     CVE-2020-25815,
     CVE-2020-25827,
     CVE-2020-25828,
     CVE-2020-25869

Multiple security issues were discovered in MediaWiki: SpecialUserRights could
leak whether a user existed or not, multiple code paths lacked HTML
sanitisation allowing for cross-site scripting and TOTP validation applied
insufficient rate limiting against brute force attempts (CVE-2020-25812,
CVE-2020-25813, CVE-2020-25814, CVE-2020-25815, CVE-2020-25827,
CVE-2020-25828).

Possible issues with actors not being loaded from the correct database or wiki
(CVE-2020-25869).

References:
- https://bugs.mageia.org/show_bug.cgi?id=27331
- https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/3VXQLPPJ77EZS3V4GMLWRHFDMOFPAX5H/
- https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/MUBKHDTKOOFV2IOS4QS3LFINAXBT5INX/
- https://www.debian.org/security/2020/dsa-4767
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25812
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25813
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25814
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25815
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25827
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25828
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25869

SRPMS:
- 7/core/mediawiki-1.31.10-1.mga7

Mageia 2020-0381: mediawiki security update

Multiple security issues were discovered in MediaWiki: SpecialUserRights could leak whether a user existed or not, multiple code paths lacked HTML sanitisation allowing for cross-s...

Summary

Multiple security issues were discovered in MediaWiki: SpecialUserRights could leak whether a user existed or not, multiple code paths lacked HTML sanitisation allowing for cross-site scripting and TOTP validation applied insufficient rate limiting against brute force attempts (CVE-2020-25812, CVE-2020-25813, CVE-2020-25814, CVE-2020-25815, CVE-2020-25827, CVE-2020-25828).
Possible issues with actors not being loaded from the correct database or wiki (CVE-2020-25869).

References

- https://bugs.mageia.org/show_bug.cgi?id=27331

- https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/3VXQLPPJ77EZS3V4GMLWRHFDMOFPAX5H/

- https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/MUBKHDTKOOFV2IOS4QS3LFINAXBT5INX/

- https://www.debian.org/security/2020/dsa-4767

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25812

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25813

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25814

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25815

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25827

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25828

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25869

Resolution

MGASA-2020-0381 - Updated mediawiki packages fix security vulnerability

SRPMS

- 7/core/mediawiki-1.31.10-1.mga7

Severity
Publication date: 30 Sep 2020
URL: https://advisories.mageia.org/MGASA-2020-0381.html
Type: security
CVE: CVE-2020-25812, CVE-2020-25813, CVE-2020-25814, CVE-2020-25815, CVE-2020-25827, CVE-2020-25828, CVE-2020-25869

Related News