CVE-2011-4361
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.
Published
2012-01-08T11:55:19.797
Last Modified
2025-04-11T00:51:21.963
Status
Deferred
Source
[email protected]
Severity
CVSSv2: 5.0 (MEDIUM)
CVSSv2 Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
- Access Vector: NETWORK
- Access Complexity: LOW
- Authentication: NONE
- Confidentiality Impact: PARTIAL
- Integrity Impact: NONE
- Availability Impact: NONE
Exploitability Score
10.0
Impact Score
2.9
Weaknesses
Affected Vendors & Products
References
-
http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-November/000104.html
Patch, Vendor Advisory
([email protected])
-
http://openwall.com/lists/oss-security/2011/11/29/12
Mailing List, Third Party Advisory
([email protected])
-
http://openwall.com/lists/oss-security/2011/11/29/6
Mailing List, Third Party Advisory
([email protected])
-
http://www.debian.org/security/2011/dsa-2366
Third Party Advisory
([email protected])
-
https://bugzilla.redhat.com/show_bug.cgi?id=758171
Issue Tracking, Third Party Advisory
([email protected])
-
https://bugzilla.wikimedia.org/show_bug.cgi?id=32616
Issue Tracking, Patch, Vendor Advisory
([email protected])
-
http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-November/000104.html
Patch, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://openwall.com/lists/oss-security/2011/11/29/12
Mailing List, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://openwall.com/lists/oss-security/2011/11/29/6
Mailing List, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.debian.org/security/2011/dsa-2366
Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://bugzilla.redhat.com/show_bug.cgi?id=758171
Issue Tracking, Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://bugzilla.wikimedia.org/show_bug.cgi?id=32616
Issue Tracking, Patch, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)