Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 9 MGASA-2024-0155 Moderate MediaWiki Multiple Risks

mageia
Calendar Grey April 30, 2024
Dist Mageia Esm H88
Several security flaws rectified in MediaWiki versions as of April 30, 2024, posing threats to Mageia systems.
Mediawiki v1.40.0 does not validate namespaces used in XML files

Summary

Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the instance administrator. (CVE-2023-3550) An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenewmessagesmanyusers and youhavenewmessages i18n messages. This is related to MediaWiki:Youhavenewmessagesfromusers. (CVE-2023-45360) An issue was discovered in DifferenceEngine.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. diff-multi-sameuser (aka "X intermediate revisions by the same user not shown") ignores username suppression. This is an information leak. (CVE-2023-45362) An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x b...

References

- https://bugs.mageia.org/show_bug.cgi?id=33156

- https://www.cve.org/CVERecord?id=CVE-2023-3550

- https://www.cve.org/CVERecord?id=CVE-2023-45359

- https://www.cve.org/CVERecord?id=CVE-2023-45360

- https://www.cve.org/CVERecord?id=CVE-2023-45361

- https://www.cve.org/CVERecord?id=CVE-2023-45362

- https://www.cve.org/CVERecord?id=CVE-2023-45363

- https://www.cve.org/CVERecord?id=CVE-2023-45364

- https://www.cve.org/CVERecord?id=CVE-2023-51704

Resolution

SRPMS

- 9/core/mediawiki-1.35.14-1.mga9

Publication date: 30 Apr 2024
URL: https://advisories.mageia.org/MGASA-2024-0155.html
Type: security
CVE: CVE-2023-3550, CVE-2023-45359, CVE-2023-45360, CVE-2023-45361, CVE-2023-45362, CVE-2023-45363, CVE-2023-45364, CVE-2023-51704

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here