Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 7: MGASA-2020-0381 Moderate: MediaWiki Cross-Site Scripting

mageia
Calendar Grey September 30, 2020
Dist Mageia Esm H88
Mageia's mediawiki packages updated to address multiple security flaws including cross-site scripting and rate limiting.
Multiple security issues were discovered in MediaWiki: SpecialUserRights could leak whether a user existed or not, multiple code paths lacked HTML sanitisation allowing for cross-s...

Summary

Multiple security issues were discovered in MediaWiki: SpecialUserRights could leak whether a user existed or not, multiple code paths lacked HTML sanitisation allowing for cross-site scripting and TOTP validation applied insufficient rate limiting against brute force attempts (CVE-2020-25812, CVE-2020-25813, CVE-2020-25814, CVE-2020-25815, CVE-2020-25827, CVE-2020-25828).
Possible issues with actors not being loaded from the correct database or wiki (CVE-2020-25869).

References

- https://bugs.mageia.org/show_bug.cgi?id=27331

- https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/3VXQLPPJ77EZS3V4GMLWRHFDMOFPAX5H/

- https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/MUBKHDTKOOFV2IOS4QS3LFINAXBT5INX/

- https://lists.debian.org/debian-security-announce/2020/msg00174.html

- https://www.cve.org/CVERecord?id=CVE-2020-25812

- https://www.cve.org/CVERecord?id=CVE-2020-25813

- https://www.cve.org/CVERecord?id=CVE-2020-25814

- https://www.cve.org/CVERecord?id=CVE-2020-25815

- https://www.cve.org/CVERecord?id=CVE-2020-25827

- https://www.cve.org/CVERecord?id=CVE-2020-25828

- https://www.cve.org/CVERecord?id=CVE-2020-25869

Resolution

SRPMS

- 7/core/mediawiki-1.31.10-1.mga7

Publication date: 30 Sep 2020
URL: https://advisories.mageia.org/MGASA-2020-0381.html
Type: security
CVE: CVE-2020-25812, CVE-2020-25813, CVE-2020-25814, CVE-2020-25815, CVE-2020-25827, CVE-2020-25828, CVE-2020-25869

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here