Vulnerability Name: | CVE-2014-9481 (CCN-99646) | ||||||||||||
Assigned: | 2014-12-21 | ||||||||||||
Published: | 2014-12-21 | ||||||||||||
Updated: | 2020-02-05 | ||||||||||||
Summary: | The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML. | ||||||||||||
CVSS v3 Severity: | 5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-9481 Source: MISC Type: Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2014/12/21/2 Source: MISC Type: Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2015/01/03/13 Source: CCN Type: Red Hat Bugzilla Bug 1175828 (CVE-2014-9475, CVE-2014-9476, CVE-2014-9477, CVE-2014-9478, CVE-2014-9479, CVE-2014-9480, CVE-2014-9481, CVE-2014-9487) CVE-2014-9475 CVE-2014-9476 CVE-2014-9477 CVE-2014-9478 CVE-2014-9479 CVE-2014-9480 CVE-2014-9481 CVE-2014-9487 mediawiki: multiple vu Source: XF Type: UNKNOWN scribunto-mediawiki-cve20149481-info-disc(99646) Source: CCN Type: MediaWiki Web Site [MediaWiki-announce] MediaWiki Security and Maintenance Releases: 1.24.1, 1.23.8, 1.22.15 and 1.19.23 Source: CONFIRM Type: Patch, Vendor Advisory https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-December/000173.html Source: MISC Type: Vendor Advisory https://phabricator.wikimedia.org/T73167 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |