Vulnerability Name: | CVE-2020-27621 (CCN-190411) | ||||||||||||
Assigned: | 2020-10-18 | ||||||||||||
Published: | 2020-10-18 | ||||||||||||
Updated: | 2020-11-02 | ||||||||||||
Summary: | The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address of an internal Wikimedia Foundation server by omitting X-Forwarded-For data. This resulted in an inability to properly audit and attribute various user actions performed via the FileImporter extension. | ||||||||||||
CVSS v3 Severity: | 4.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N) 3.8 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-27621 Source: XF Type: UNKNOWN mediawiki-cve202027621-weak-security(190411) Source: CCN Type: MediaWiki Web site Set originalRequest (incl. X-Forwarded-For) for remote edits Source: MISC Type: Exploit, Patch, Vendor Advisory https://gerrit.wikimedia.org/r/q/I24a240253c7a5c66dd493a68e8c23d95a17e1b21 Source: CCN Type: Phabricator Web page mw-ext-FileImporter uses a WMF IP address, does not include XFF for users using this extension (CVE-2020-27621) Source: MISC Type: Exploit, Patch, Vendor Advisory https://phabricator.wikimedia.org/T265810 | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |