Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Untriaged
created 2 months ago Activity log
  • Created suggestion
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, …

The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.

Affected products

MediaWiki
  • ==1.20.x before 1.20.8
  • ==1.21.x before 1.21.3
  • ==before 1.19.9

Matching in nixpkgs

Package maintainers