Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8 MGASA-2022-0338 Moderate: MediaWiki Security Fix

mageia
Calendar Grey September 16, 2022
Dist Mageia Esm H88
Mageia 2022-0340 updates PHP packages to enhance performance with various improvements for optimal functionality.
Username is not escaped in the "welcomeuser" message (T308471)

Summary

Username is not escaped in the "welcomeuser" message (T308471).
Bundled guzzlehttp/guzzle has been updated to 6.5.8, fixing several issues (CVE-2022-29248, CVE-2022-31042, CVE-2022-31043, CVE-2022-31090, CVE-2022-31091).

References

- https://bugs.mageia.org/show_bug.cgi?id=30837

- https://github.com/guzzle/guzzle/security/advisories/GHSA-cwmx-hcrq-mhc3

- https://github.com/guzzle/guzzle/security/advisories/GHSA-w248-ffj2-4v5q

- https://github.com/guzzle/guzzle/security/advisories/GHSA-f2wf-25xc-69c9

- https://github.com/guzzle/guzzle/security/advisories/GHSA-q559-8m2m-g699

- https://github.com/guzzle/guzzle/security/advisories/GHSA-25mq-v84q-4j7r

- https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/thread/PIPYDRSHXOYW5DB7X755QDNUV5EZWPWB/

- https://www.cve.org/CVERecord?id=CVE-2022-29248

- https://www.cve.org/CVERecord?id=CVE-2022-31042

- https://www.cve.org/CVERecord?id=CVE-2022-31043

- https://www.cve.org/CVERecord?id=CVE-2022-31090

- https://www.cve.org/CVERecord?id=CVE-2022-31091

Resolution

SRPMS

- 8/core/mediawiki-1.35.7-1.mga8

Publication date: 16 Sep 2022
URL: https://advisories.mageia.org/MGASA-2022-0338.html
Type: security
CVE: CVE-2022-29248, CVE-2022-31042, CVE-2022-31043, CVE-2022-31090, CVE-2022-31091

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here