[FREEBSD:95DAD123-180E-11EE-86BA-080027EDA32C] mediawiki -- multiple vulnerabilities

Severity High
Affected Packages 3
CVEs 3

Mediawiki reports:

  (T335203, CVE-2023-29197) Upgrade guzzlehttp/psr7 to >= 1.9.1/2.4.5.
  (T335612, CVE-2023-36674) Manualthumb bypasses badFile lookup.
  (T332889, CVE-2023-36675) XSS in BlockLogFormatter due to unsafe message
    use.
Package Affected Version
pkg:freebsd/mediawiki139 < 1.39.4
pkg:freebsd/mediawiki138 < 1.38.7
pkg:freebsd/mediawiki135 < 1.35.11
ID
FREEBSD:95DAD123-180E-11EE-86BA-080027EDA32C
Severity
high
Severity from
CVE-2023-29197
URL
http://vuxml.freebsd.org/freebsd/95dad123-180e-11ee-86ba-080027eda32c.html
Published
2023-04-21T00:00:00
(17 months ago)
Modified
2023-07-01T00:00:00
(14 months ago)
Rights
FreeBSD VuXML Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/mediawiki139 mediawiki139 < 1.39.4
Affected pkg:freebsd/mediawiki138 mediawiki138 < 1.38.7
Affected pkg:freebsd/mediawiki135 mediawiki135 < 1.35.11
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...