Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xpv7-93cm-4mxv

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью

Описание

img_auth.php may leak private extension images into the public cache

In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.

Пакеты

Наименование

mediawiki/core

composer
Затронутые версииВерсия исправления

< 1.31.8

1.31.8

Наименование

mediawiki/core

composer
Затронутые версииВерсия исправления

>= 1.32.0, < 1.33.4

1.33.4

Наименование

mediawiki/core

composer
Затронутые версииВерсия исправления

>= 1.34.0, < 1.34.2

1.34.2

EPSS

Процентиль: 72%
0.00737
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.1
ubuntu
больше 5 лет назад

In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.

CVSS3: 3.1
redhat
больше 5 лет назад

In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.

CVSS3: 3.1
nvd
больше 5 лет назад

In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.

CVSS3: 3.1
debian
больше 5 лет назад

In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34. ...

CVSS3: 3.1
fstec
больше 5 лет назад

Уязвимость компонента img_auth.php программного средства для реализации гипертекстовой среды MediaWik, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 72%
0.00737
Низкий

Дефекты

CWE-200