[FREEBSD:95DAD123-180E-11EE-86BA-080027EDA32C] mediawiki -- multiple vulnerabilities
Severity
High
Affected Packages
3
CVEs
3
Mediawiki reports:
(T335203, CVE-2023-29197) Upgrade guzzlehttp/psr7 to >= 1.9.1/2.4.5.
(T335612, CVE-2023-36674) Manualthumb bypasses badFile lookup.
(T332889, CVE-2023-36675) XSS in BlockLogFormatter due to unsafe message
use.
Package | Affected Version |
---|---|
pkg:freebsd/mediawiki139 | < 1.39.4 |
pkg:freebsd/mediawiki138 | < 1.38.7 |
pkg:freebsd/mediawiki135 | < 1.35.11 |
- ID
- FREEBSD:95DAD123-180E-11EE-86BA-080027EDA32C
- Severity
- high
- Severity from
- CVE-2023-29197
- URL
- http://vuxml.freebsd.org/freebsd/95dad123-180e-11ee-86ba-080027eda32c.html
- Published
-
2023-04-21T00:00:00
(17 months ago) - Modified
-
2023-07-01T00:00:00
(14 months ago) - Rights
- FreeBSD VuXML Security Team
- Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
FreeBSD VuXML | https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/HVT3U3XYY35PSCIQPHMY4VQNF3Q6MHUO/ |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:freebsd/mediawiki139 | mediawiki139 | < 1.39.4 | ||||
Affected | pkg:freebsd/mediawiki138 | mediawiki138 | < 1.38.7 | ||||
Affected | pkg:freebsd/mediawiki135 | mediawiki135 | < 1.35.11 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |