Updated mediawiki packages fix security vulnerability
Publication date: 10 Jul 2020Modification date: 10 Jul 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-XXXX
Description
Updated mediawiki packages fix security vulnerability: In MediaWiki before 1.31.8, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled (CVE-2020-15005).
References
SRPMS
7/core
- mediawiki-1.31.8-1.mga7