Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-15005

Опубликовано: 24 июн. 2020
Источник: redhat
CVSS3: 3.1

Описание

In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.

Отчет

The mediawiki package was removed from Red Hat OpenShift Container Platform in version 4.3.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11mediawikiFix deferred
Red Hat OpenShift Container Platform 4mediawikiFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1851026mediawiki: possible leak of private extension images into public cache

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
больше 5 лет назад

In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.

CVSS3: 3.1
nvd
больше 5 лет назад

In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.

CVSS3: 3.1
debian
больше 5 лет назад

In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34. ...

github
больше 3 лет назад

img_auth.php may leak private extension images into the public cache

CVSS3: 3.1
fstec
больше 5 лет назад

Уязвимость компонента img_auth.php программного средства для реализации гипертекстовой среды MediaWik, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

3.1 Low

CVSS3