mediawiki: non-jqueryMsg version of mw.message().parse() doesn't escape HTML leads to XSS
Published Sep 27, 2020
6.1
MEDIUMCVSS 3.1
EPSS 1.09%
Description
An issue was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. The non-jqueryMsg version of mw.message().parse() doesn't escape HTML. This affects both message contents (which are generally safe) and the parameters (which can be based on user input). (When jqueryMsg is loaded, it correctly accepts only whitelisted tags in message contents, and escapes all parameters. Situations with an unloaded jqueryMsg are rare in practice, but can for example occur for Special:SpecialPages on a wiki with no extensions installed.)
Affected products
No data.
No data.
Red Hat OpenShift Container Platform 3.11
mediawiki
Not affected
Red Hat OpenShift Container Platform 4
mediawiki
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | mediawiki | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | mediawiki | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
OpenShift Container Platform (OCP) delivers the mediawiki package, but the vulnerable code is not bundled, therefore OCP is not affected by this flaw.
References (13)
- https://access.redhat.com/security/cve/CVE-2020-25828 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1903776 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4110 Advisory
- https://github.com/FriendsOfPHP/security-advisories/blob/master/mediawiki/core/CVE-2020-25828.yaml
- https://github.com/advisories/GHSA-h8qx-mj6v-2934 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6
- https://lists.wikimedia.org/pipermail/mediawiki-announce x_refsource_MISCVendor Advisory
- https://lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048480.html x_refsource_CONFIRMMailing ListVendor Advisory
- https://lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048488.html x_refsource_MISCMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-25828
- https://phabricator.wikimedia.org/T115888
- https://www.cve.org/CVERecord?id=CVE-2020-25828
Change history (0)
No recorded changes yet.