Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-41801

Опубликовано: 11 окт. 2021
Источник: debian

Описание

The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog)

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mediawikifixed1:1.35.4-1package
mediawikinot-affectedstretchpackage

Примечания

  • https://lists.wikimedia.org/hyperkitty/list/wikitech-l@lists.wikimedia.org/thread/2IFS5CM2YV4VMSODPX3J2LFHKSEWVFV5/

  • https://phabricator.wikimedia.org/T279090

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 4 лет назад

The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog)

CVSS3: 8.8
nvd
больше 4 лет назад

The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog)

CVSS3: 8.8
github
больше 3 лет назад

The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog)