Все бюллетени/t7/ALT-PU-2014-1984-1
ALT-PU-2014-1984-1

Обновление пакета mediawiki в ветке t7

Версия1.23.1-alt0.M70P.1
Задание#126791
Опубликовано2014-08-03
Макс. серьёзностьMEDIUM
Серьёзность:

Закрытые проблемы (3)

CVE-2014-2665
MEDIUM4.0

includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x before 1.22.5 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account, as demonstrated by tracking the victim's activity, related to a "login CSRF" issue.

Опубликовано: 2014-04-20Изменено: 2025-04-12
CVSS 2.0СРЕДНЯЯ 4.0
CVSS:2.0/AV:N/AC:L/Au:S/C:P/I:N/A:N