Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 7, 8: 2021-0346 Critical: MediaWiki Bot API Access Issue

mageia
Calendar Grey July 12, 2021
Dist Mageia Esm H88
Enhancements for MediaWiki address unauthorized bot access through APIs, bolstering security for Mageia users.
In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access

Summary

In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented) (CVE-2021-35197).
The mediawiki packages are upgraded to latest version for their branches. See upstream release notes for other bugfixes.

References

- https://bugs.mageia.org/show_bug.cgi?id=29190

- https://www.mediawiki.org/wiki/Release_notes/1.35#MediaWiki_1.35.3

- https://www.mediawiki.org/wiki/MediaWiki_1.31

- https://www.cve.org/CVERecord?id=CVE-2021-35197

Resolution

SRPMS

- 7/core/mediawiki-1.31.15-1.mga7

- 8/core/mediawiki-1.35.3-1.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 12 Jul 2021
URL: https://advisories.mageia.org/MGASA-2021-0346.html
Type: security
CVE: CVE-2021-35197

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here