Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-45038

Опубликовано: 16 дек. 2021
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.

A flaw was found in mediawiki. The "rollback" feature (action=rollback) could be passed a specially crafted parameter that allowed an attacker to view the contents of arbitrary pages, regardless of whether they had permissions to do so.

Отчет

The mediawiki package was removed from OpenShift Container Platform (OCP) in version 4.3, therefore for OCP 4 has been marked as out of support scope.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11mediawikiOut of support scope
Red Hat OpenShift Container Platform 4mediawikiOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200

EPSS

Процентиль: 70%
0.0135
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.

CVSS3: 5.3
nvd
больше 4 лет назад

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.

CVSS3: 5.3
debian
больше 4 лет назад

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36 ...

CVSS3: 5.3
github
больше 4 лет назад

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.

EPSS

Процентиль: 70%
0.0135
Низкий

5.3 Medium

CVSS3