Vulnerability Name: | CVE-2015-2940 (CCN-102463) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2015-03-21 | ||||||||||||||||||||||||||||||||||||
Published: | 2015-03-21 | ||||||||||||||||||||||||||||||||||||
Updated: | 2016-12-07 | ||||||||||||||||||||||||||||||||||||
Summary: | Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of certain users for requests that retrieve sensitive user information via unspecified vectors. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-352 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-2940 Source: MANDRIVA Type: UNKNOWN MDVSA-2015:200 Source: MLIST Type: UNKNOWN [oss-security] 20150331 CVE request: MediaWiki 1.24.2/1.23.9/1.19.24 Source: CCN Type: oss-security Mailing List, Tue, 7 Apr 2015 03:34:12 -0400 (EDT) Re: CVE request: MediaWiki 1.24.2/1.23.9/1.19.24 Source: MLIST Type: UNKNOWN [oss-security] 20150407 Re: CVE request: MediaWiki 1.24.2/1.23.9/1.19.24 Source: BID Type: UNKNOWN 73477 Source: CCN Type: BID-73477 MediaWiki Multiple Security Vulnerabilities Source: XF Type: UNKNOWN mediawiki-cve20152940-csrf(102463) Source: CCN Type: MediaWiki Web Site [MediaWiki-announce] MediaWiki Security and Maintenance Releases: 1.19.24, 1.23.9, and 1.24.2 Source: MLIST Type: Patch, Vendor Advisory [MediaWiki-announce] 20150331 MediaWiki Security and Maintenance Releases: 1.19.24, 1.23.9, and 1.24.2 Source: CONFIRM Type: UNKNOWN https://phabricator.wikimedia.org/T85858 Source: GENTOO Type: UNKNOWN GLSA-201510-05 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-2940 | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |