Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-29004

Опубликовано: 22 дек. 2020
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11mediawikiNot affected
Red Hat OpenShift Container Platform 4mediawikiNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-304
https://bugzilla.redhat.com/show_bug.cgi?id=1922230mediawiki: Missing edit token in ApiPushBase.php facilitates CSRF attacks

EPSS

Процентиль: 51%
0.00701
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack.

github
больше 4 лет назад

The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack.

EPSS

Процентиль: 51%
0.00701
Низкий

5.9 Medium

CVSS3

Уязвимость CVE-2020-29004