Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4c6h-6j8p-jf37

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

EPSS

Процентиль: 67%
0.00551
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 14 лет назад

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

nvd
больше 14 лет назад

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

debian
больше 14 лет назад

api.php in MediaWiki before 1.15.5 does not prevent use of public cach ...

EPSS

Процентиль: 67%
0.00551
Низкий

Дефекты

CWE-200