Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hh63-773r-23jr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address of an internal Wikimedia Foundation server by omitting X-Forwarded-For data. This resulted in an inability to properly audit and attribute various user actions performed via the FileImporter extension.

The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address of an internal Wikimedia Foundation server by omitting X-Forwarded-For data. This resulted in an inability to properly audit and attribute various user actions performed via the FileImporter extension.

EPSS

Процентиль: 49%
0.00264
Низкий

Связанные уязвимости

CVSS3: 4.3
nvd
больше 5 лет назад

The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address of an internal Wikimedia Foundation server by omitting X-Forwarded-For data. This resulted in an inability to properly audit and attribute various user actions performed via the FileImporter extension.

EPSS

Процентиль: 49%
0.00264
Низкий