Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 7 Security Advisory: MediaWiki 2021-0086 Critical HTML Injection

mageia
Calendar Grey February 19, 2021
Dist Mageia Esm H88
A vulnerability in MediaWiki has been resolved through new package updates for Mageia. This fixes issues related to XSS attacks and potential information leaks.
In MediaWiki before 1.31.11, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML

Summary

In MediaWiki before 1.31.11, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights, and the table on the left side has unchangeable groups in it. The right column with the changeable groups is not affected and is escaped correctly (CVE-2020-35475).
MediaWiki before 1.31.11 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main Page, visits a log entry on Special:Log, and toggles the "Change visibility of selected log entries" checkbox (or a tags checkbox) next to it, there is a redirection to the main page's action=historysubmit instead of the desired behavior in which a revision-deletion form appears (CVE-2020-35477).
MediaWiki before 1.31.11 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of ...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=27781

- https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/X2TKK7TINY7UEGNSXVX2KE54IACBCR4L/

- https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/7PJKIVUOH7MLVTGOEXAKNWJ4RWRVKGSK/

- https://lists.debian.org/debian-security-announce/2020/msg00223.html

- https://www.cve.org/CVERecord?id=CVE-2020-35475

- https://www.cve.org/CVERecord?id=CVE-2020-35477

- https://www.cve.org/CVERecord?id=CVE-2020-35479

- https://www.cve.org/CVERecord?id=CVE-2020-35480

Resolution

SRPMS

- 7/core/mediawiki-1.31.12-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 19 Feb 2021
URL: https://advisories.mageia.org/MGASA-2021-0086.html
Type: security
CVE: CVE-2020-35475, CVE-2020-35477, CVE-2020-35479, CVE-2020-35480

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here