MEDIUM
mediawiki: LogEventList:: getFiltersDesc is insecurely using message text to build options names for HTML multi-select field
Published Sep 27, 2020
6.1
MEDIUMCVSS 3.1
EPSS 1.10%
Description
An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The relevant code should use escaped() instead of text().
Affected products
No data.
Configuration 2
- 33
No data.
Red Hat OpenShift Container Platform 3.11
mediawiki
Not affected
Red Hat OpenShift Container Platform 4
mediawiki
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | mediawiki | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | mediawiki | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
OpenShift Container Platform (OCP) delivers the mediawiki package, but the vulnerable code is not bundled, therefore OCP is not affected by this flaw.
Weaknesses (1)
References (13)
- https://access.redhat.com/security/cve/CVE-2020-25815 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1903759 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1972 Advisory
- https://gerrit.wikimedia.org/g/mediawiki/core/+/ec76e14be658187544f07c1a249a047e1a75eaf8/includes/logging/LogEventsList.php#214 x_refsource_MISCPatchVendor Advisory
- https://github.com/FriendsOfPHP/security-advisories/blob/master/mediawiki/core/CVE-2020-25815.yaml
- https://github.com/advisories/GHSA-2f58-vf6g-6p8x Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6
- https://lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048480.html x_refsource_CONFIRMMailing ListVendor Advisory
- https://lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048488.html x_refsource_MISCMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-25815
- https://phabricator.wikimedia.org/T256171
- https://www.cve.org/CVERecord?id=CVE-2020-25815
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 27, 2020
Updated Aug 4, 2024
Reserved Sep 23, 2020
Link CVE-2020-25815
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-1972 GHSA-2F58-VF6G-6P8X Assigner mitre
Published Sep 27, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2022-1972