HIGH
mediawiki: handling of actor ID does not necessarily use the correct database or correct wiki leads to information disclosure
Published Sep 27, 2020
7.5
HIGHCVSS 3.1
EPSS 1.41%
Description
An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of actor ID does not necessarily use the correct database or correct wiki.
Affected products
No data.
No data.
Red Hat OpenShift Container Platform 3.11
mediawiki
Not affected
Red Hat OpenShift Container Platform 4
mediawiki
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | mediawiki | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | mediawiki | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
OpenShift Container Platform (OCP) delivers the mediawiki package, but the vulnerable code is not bundled, therefore OCP is not affected by this flaw.
References (8)
- https://access.redhat.com/security/cve/CVE-2020-25869 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1903770 Issue Tracking
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6/ vendor-advisoryx_refsource_FEDORA
- https://lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048480.html x_refsource_CONFIRMMailing ListVendor Advisory
- https://lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048488.html x_refsource_MISCMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-25869
- https://phabricator.wikimedia.org/T260485 x_refsource_MISCPermissions RequiredVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-25869
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-25869 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1903770 | Issue Tracking | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTTPZ7XMDS66I442OLLHXBDNP2LCBJU6/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048480.html | x_refsource_CONFIRMMailing ListVendor Advisory | |
| https://lists.wikimedia.org/pipermail/mediawiki-l/2020-September/048488.html | x_refsource_MISCMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-25869 | ||
| https://phabricator.wikimedia.org/T260485 | x_refsource_MISCPermissions RequiredVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-25869 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 27, 2020
Updated Aug 4, 2024
Reserved Sep 24, 2020
Link CVE-2020-25869
CISA Vulnrichment
Updated n/a