Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-15005

Опубликовано: 24 июн. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.6
CVSS3: 3.1

Описание

In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

released

1:1.31.8-1
eoan

ignored

end of life
esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

released

1:1.31.8-1
esm-apps/noble

released

1:1.31.8-1
esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needed
groovy

released

1:1.31.8-1

Показывать по

EPSS

Процентиль: 72%
0.00737
Низкий

2.6 Low

CVSS2

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
redhat
больше 5 лет назад

In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.

CVSS3: 3.1
nvd
больше 5 лет назад

In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.

CVSS3: 3.1
debian
больше 5 лет назад

In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34. ...

github
больше 3 лет назад

img_auth.php may leak private extension images into the public cache

CVSS3: 3.1
fstec
больше 5 лет назад

Уязвимость компонента img_auth.php программного средства для реализации гипертекстовой среды MediaWik, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 72%
0.00737
Низкий

2.6 Low

CVSS2

3.1 Low

CVSS3