Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestions search

With package: mediawiki

Found 36 matching suggestions

View:
Compact
Detailed
Untriaged
created 2 months ago Activity log
  • Created suggestion
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, …

The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.

Affected products

MediaWiki
  • ==1.20.x before 1.20.8
  • ==1.21.x before 1.21.3
  • ==before 1.19.9

Matching in nixpkgs

Package maintainers

Untriaged
created 2 months ago Activity log
  • Created suggestion
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers …

MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.

References

Affected products

mediawiki
  • ==1.19.4
  • ==1.20.3

Matching in nixpkgs

Package maintainers

Untriaged
created 2 months ago Activity log
  • Created suggestion
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error …

MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.

Affected products

mediawiki
  • ==1.19.4
  • ==1.20.3

Matching in nixpkgs

Package maintainers

Untriaged
created 2 months ago Activity log
  • Created suggestion
includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, …

includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not properly detect extensions when there are an even number of "." (period) characters in a string, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the siprop parameter in a query action to wiki/api.php.

Affected products

MediaWiki
  • ==and 1.21.x before 1.21.2
  • ==1.19.x before 1.19.8
  • ==1.20.x before 1.20.7

Matching in nixpkgs

Package maintainers

Untriaged
created 2 months ago Activity log
  • Created suggestion
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, …

The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.

Affected products

MediaWiki
  • ==1.2x before 1.21.4
  • ==before 1.19.10
  • ==1.22.x before 1.22.1

Matching in nixpkgs

Package maintainers

Untriaged
created 2 months ago Activity log
  • Created suggestion
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and …

A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.

Affected products

MediaWiki
  • ==before 1.19.5 and 1.20.x before 1.20.4

Matching in nixpkgs

Package maintainers

Untriaged
created 2 months ago Activity log
  • Created suggestion
Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x …

Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via unspecified CSS values.

Affected products

MediaWiki
  • ==1.2x before 1.21.4
  • ==1.19.9 before 1.19.10
  • ==1.22.x before 1.22.1

Matching in nixpkgs

Package maintainers

Untriaged
created 2 months ago Activity log
  • Created suggestion
mediawiki allows deleted text to be exposed

mediawiki allows deleted text to be exposed

Affected products

mediawiki
  • ==1.16

Matching in nixpkgs

Package maintainers

Untriaged
created 2 months ago Activity log
  • Created suggestion
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in …

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.

Affected products

MediaWiki
  • ==1.19.x before 1.19.2
  • ==before 1.18.5

Matching in nixpkgs

Package maintainers

Untriaged
created 2 months, 2 weeks ago Activity log
  • Created suggestion
Action API xslt option allows JavaScript execution by administrators who are not interface administrators

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFormatXml.Php. This issue affects MediaWiki: from * before 1.39.16, 1.43.6, 1.44.3, 1.45.1.

Affected products

MediaWiki
  • <1.39.16, 1.43.6, 1.44.3, 1.45.1

Matching in nixpkgs

Package maintainers