Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rmqj-6c77-6qch

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an IP address is contained in two ranges, one of which is locally disabled.

In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an IP address is contained in two ranges, one of which is locally disabled.

EPSS

Процентиль: 55%
0.00321
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 8.1
redhat
почти 6 лет назад

In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an IP address is contained in two ranges, one of which is locally disabled.

CVSS3: 9.8
nvd
почти 6 лет назад

In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an IP address is contained in two ranges, one of which is locally disabled.

EPSS

Процентиль: 55%
0.00321
Низкий

Дефекты

CWE-269