Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4c6h-6j8p-jf37

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

EPSS

Процентиль: 67%
0.00551
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 15 лет назад

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

nvd
почти 15 лет назад

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

debian
почти 15 лет назад

api.php in MediaWiki before 1.15.5 does not prevent use of public cach ...

EPSS

Процентиль: 67%
0.00551
Низкий

Дефекты

CWE-200