Updated mediawiki packages fix security vulnerability
Publication date: 30 Sep 2020Modification date: 30 Sep 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-25812 , CVE-2020-25813 , CVE-2020-25814 , CVE-2020-25815 , CVE-2020-25827 , CVE-2020-25828 , CVE-2020-25869
Description
Multiple security issues were discovered in MediaWiki: SpecialUserRights could leak whether a user existed or not, multiple code paths lacked HTML sanitisation allowing for cross-site scripting and TOTP validation applied insufficient rate limiting against brute force attempts (CVE-2020-25812, CVE-2020-25813, CVE-2020-25814, CVE-2020-25815, CVE-2020-25827, CVE-2020-25828). Possible issues with actors not being loaded from the correct database or wiki (CVE-2020-25869).
References
- https://bugs.mageia.org/show_bug.cgi?id=27331
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-September/000260.html
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-September/000262.html
- https://www.debian.org/security/2020/dsa-4767
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25812
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25813
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25814
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25815
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25827
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25828
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25869
SRPMS
7/core
- mediawiki-1.31.10-1.mga7