[FREEBSD:BE1AADA2-BE6C-11E8-8FC6-000C29434208] mediawiki -- multiple vulnerabilities
Severity
Medium
Affected Packages
4
CVEs
3
Mediawiki reports:
Security fixes:
T169545: $wgRateLimits entry for 'user' overrides 'newbie'.
T194605: BotPasswords can bypass CentralAuth's account lock.
T187638: When a log event is (partially) hidden Special:Redirect/logid
can link to the incorrect log and reveal hidden
T193237: Special:BotPasswords should require reauthenticate.
Package | Affected Version |
---|---|
pkg:freebsd/mediawiki131 | < 1.31.1 |
pkg:freebsd/mediawiki130 | < 1.30.1 |
pkg:freebsd/mediawiki129 | |
pkg:freebsd/mediawiki127 | < 1.27.5 |
- ID
- FREEBSD:BE1AADA2-BE6C-11E8-8FC6-000C29434208
- Severity
- medium
- Severity from
- CVE-2018-0505
- URL
- http://vuxml.freebsd.org/freebsd/be1aada2-be6c-11e8-8fc6-000c29434208.html
- Published
-
2018-08-29T00:00:00
(6 years ago) - Modified
-
2018-09-22T00:00:00
(6 years ago) - Rights
- FreeBSD VuXML Security Team
- Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
FreeBSD VuXML | https://lists.wikimedia.org/pipermail/mediawiki-announce/2018-September/000223.html |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:freebsd/mediawiki131 | mediawiki131 | < 1.31.1 | ||||
Affected | pkg:freebsd/mediawiki130 | mediawiki130 | < 1.30.1 | ||||
Affected | pkg:freebsd/mediawiki129 | mediawiki129 | |||||
Affected | pkg:freebsd/mediawiki127 | mediawiki127 | < 1.27.5 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |