跳转到帖子

MediaWiki: Unspecified Security Vulnerability (CVE-2023-29141)

recommended_posts

发布于
  • Members

MediaWiki: Unspecified Security Vulnerability (CVE-2023-29141)

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
03/31/2023
Created
05/05/2023
Added
04/12/2023
Modified
01/28/2025

Description

An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header.

Solution(s)

  • mediawiki-upgrade-1_35_10
  • mediawiki-upgrade-1_38_6
  • mediawiki-upgrade-1_39_3

References

  • https://attackerkb.com/topics/cve-2023-29141
  • CVE - 2023-29141
  • https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/core/+/REL1_39/RELEASE-NOTES-1.39
  • https://lists.debian.org/debian-lts-announce/2023/08/msg00029.html
  • https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ONWHGOBFD6CQAEGOP5O375XAP2N6RUHT/
  • https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZGK4NZPIJ5ET2ANRZOUYPCRIB5I64JR7/
  • https://phabricator.wikimedia.org/T285159
  • https://www.debian.org/security/2023/dsa-5447
View more
  • 查看数 696
  • 已创建
  • 最后回复