Vulnerability Name: | CVE-2020-15005 (CCN-184341) | ||||||||||||
Assigned: | 2020-03-31 | ||||||||||||
Published: | 2020-03-31 | ||||||||||||
Updated: | 2021-07-21 | ||||||||||||
Summary: | In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled. | ||||||||||||
CVSS v3 Severity: | 3.1 Low (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N) 2.7 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-15005 Source: XF Type: UNKNOWN mediawiki-cve202015005-info-disc(184341) Source: CONFIRM Type: Release Notes, Vendor Advisory https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/core/+/REL1_31/RELEASE-NOTES-1.31 Source: CONFIRM Type: Release Notes, Vendor Advisory https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/core/+/REL1_33/RELEASE-NOTES-1.33 Source: CONFIRM Type: Release Notes, Vendor Advisory https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/core/+/REL1_34/RELEASE-NOTES-1.34 Source: MLIST Type: Mailing List, Third Party Advisory [debian-lts-announce] 20201223 [SECURITY] [DLA 2504-1] mediawiki security update Source: FEDORA Type: Third Party Advisory FEDORA-2020-9c97633708 Source: CONFIRM Type: Mailing List, Release Notes, Vendor Advisory https://lists.wikimedia.org/pipermail/wikitech-l/2020-June/093535.html Source: CCN Type: Phabricator Web page img_auth.php may leak private extension images into the public cache (CVE-2020-15005) Source: MISC Type: Patch, Vendor Advisory https://phabricator.wikimedia.org/T248947 Source: DEBIAN Type: Third Party Advisory DSA-4767 Source: CCN Type: MediaWiki Web site MediaWiki Source: CCN Type: WhiteSource Vulnerability Database CVE-2020-15005 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |