Mageia 2020-0381: mediawiki security update
Summary
Multiple security issues were discovered in MediaWiki: SpecialUserRights could
leak whether a user existed or not, multiple code paths lacked HTML
sanitisation allowing for cross-site scripting and TOTP validation applied
insufficient rate limiting against brute force attempts (CVE-2020-25812,
CVE-2020-25813, CVE-2020-25814, CVE-2020-25815, CVE-2020-25827,
CVE-2020-25828).
Possible issues with actors not being loaded from the correct database or wiki
(CVE-2020-25869).
References
- https://bugs.mageia.org/show_bug.cgi?id=27331
- https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/3VXQLPPJ77EZS3V4GMLWRHFDMOFPAX5H/
- https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/MUBKHDTKOOFV2IOS4QS3LFINAXBT5INX/
- https://www.debian.org/security/2020/dsa-4767
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25812
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25813
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25814
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25815
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25827
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25828
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25869
Resolution
MGASA-2020-0381 - Updated mediawiki packages fix security vulnerability
SRPMS
- 7/core/mediawiki-1.31.10-1.mga7