MEDIUM
api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim
Published Apr 27, 2011
4.3
MEDIUMCVSS 2.0
EPSS 1.65%
Description
api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.
Affected products
No data.
OR
- ≤ 1.15.4
- 1.1.0
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.2.6
- 1.3
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.3.5
- 1.3.6
- 1.3.7
- 1.3.8
- 1.3.9
- 1.3.10
- 1.3.11
- 1.3.12
- 1.3.13
- 1.3.14
- 1.3.15
- 1.4
- 1.4
- 1.4
- 1.4
- 1.4
- 1.4
- 1.4.0
- 1.4.1
- 1.4.2
- 1.4.3
- 1.4.4
- 1.4.5
- 1.4.6
- 1.4.7
- 1.4.8
- 1.4.9
- 1.4.10
- 1.4.11
- 1.4.12
- 1.4.13
- 1.4.14
- 1.5
- 1.5
- 1.5
- 1.5
- 1.5
- 1.5
- 1.5
- 1.5
- 1.5
- 1.5.0
- 1.5.1
- 1.5.2
- 1.5.3
- 1.5.4
- 1.5.5
- 1.5.6
- 1.5.7
- 1.5.8
- 1.10.0
- 1.10.0
- 1.10.0
- 1.10.1
- 1.10.2
- 1.10.3
- 1.10.4
- 1.11
- 1.11
- 1.11.0
- 1.11.1
- 1.11.2
- 1.12.0
- 1.12.0
- 1.12.1
- 1.12.2
- 1.12.3
- 1.12.4
- 1.13.0
- 1.13.0
- 1.13.0
- 1.13.1
- 1.13.2
- 1.13.3
- 1.13.4
- 1.14.0
- 1.15.0
- 1.15.1
- 1.15.2
- 1.15.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058588.html vendor-advisoryx_refsource_FEDORAPatch
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059232.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059235.html vendor-advisoryx_refsource_FEDORA
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-July/000092.html mailing-listx_refsource_MLISTPatchVendor Advisory
- http://openwall.com/lists/oss-security/2010/07/29/4 mailing-listx_refsource_MLISTPatch
- http://svn.wikimedia.org/viewvc/mediawiki?view=revision&revision=69776 x_refsource_CONFIRMPatch
- http://www.securityfocus.com/bid/42019 vdb-entryx_refsource_BIDPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=620224 x_refsource_CONFIRMPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=620226 x_refsource_CONFIRMPatch
- https://bugzilla.wikimedia.org/show_bug.cgi?id=24565 x_refsource_CONFIRM
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 27, 2011
Updated Aug 7, 2024
Reserved Jul 22, 2010
Link CVE-2010-2787
CISA Vulnrichment
Updated n/a