MGASA-2022-0338 - Updated mediawiki packages fix security vulnerability

Publication date: 16 Sep 2022
URL: https://advisories.mageia.org/MGASA-2022-0338.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2022-29248,
     CVE-2022-31042,
     CVE-2022-31043,
     CVE-2022-31090,
     CVE-2022-31091

Username is not escaped in the "welcomeuser" message (T308471).

Bundled guzzlehttp/guzzle has been updated to 6.5.8, fixing several issues
(CVE-2022-29248, CVE-2022-31042, CVE-2022-31043, CVE-2022-31090,
CVE-2022-31091).

References:
- https://bugs.mageia.org/show_bug.cgi?id=30837
- https://github.com/guzzle/guzzle/security/advisories/GHSA-cwmx-hcrq-mhc3
- https://github.com/guzzle/guzzle/security/advisories/GHSA-w248-ffj2-4v5q
- https://github.com/guzzle/guzzle/security/advisories/GHSA-f2wf-25xc-69c9
- https://github.com/guzzle/guzzle/security/advisories/GHSA-q559-8m2m-g699
- https://github.com/guzzle/guzzle/security/advisories/GHSA-25mq-v84q-4j7r
- https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/thread/PIPYDRSHXOYW5DB7X755QDNUV5EZWPWB/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29248
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31042
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31043
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31090
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31091

SRPMS:
- 8/core/mediawiki-1.35.7-1.mga8

Mageia 2022-0338: mediawiki security update

Username is not escaped in the "welcomeuser" message (T308471)

Summary

Username is not escaped in the "welcomeuser" message (T308471).
Bundled guzzlehttp/guzzle has been updated to 6.5.8, fixing several issues (CVE-2022-29248, CVE-2022-31042, CVE-2022-31043, CVE-2022-31090, CVE-2022-31091).

References

- https://bugs.mageia.org/show_bug.cgi?id=30837

- https://github.com/guzzle/guzzle/security/advisories/GHSA-cwmx-hcrq-mhc3

- https://github.com/guzzle/guzzle/security/advisories/GHSA-w248-ffj2-4v5q

- https://github.com/guzzle/guzzle/security/advisories/GHSA-f2wf-25xc-69c9

- https://github.com/guzzle/guzzle/security/advisories/GHSA-q559-8m2m-g699

- https://github.com/guzzle/guzzle/security/advisories/GHSA-25mq-v84q-4j7r

- https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/thread/PIPYDRSHXOYW5DB7X755QDNUV5EZWPWB/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29248

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31042

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31043

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31090

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31091

Resolution

MGASA-2022-0338 - Updated mediawiki packages fix security vulnerability

SRPMS

- 8/core/mediawiki-1.35.7-1.mga8

Severity
Publication date: 16 Sep 2022
URL: https://advisories.mageia.org/MGASA-2022-0338.html
Type: security
CVE: CVE-2022-29248, CVE-2022-31042, CVE-2022-31043, CVE-2022-31090, CVE-2022-31091

Related News