vulnerability

FreeBSD: VID-0A50BB48-625F-11EC-A1FB-080027CB2F6F (CVE-2021-44854): mediawiki -- multiple vulnerabilities

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Dec 1, 2021
Added
Nov 4, 2022
Modified
Jan 28, 2025

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-0A50BB48-625F-11EC-A1FB-080027CB2F6F:




Mediawiki reports:



(T292763. CVE-2021-44854) REST API incorrectly publicly caches


autocomplete search results from private wikis.


(T271037, CVE-2021-44856) Title blocked in AbuseFilter can be created via


Special:ChangeContentModel.


(T297322, CVE-2021-44857) Unauthorized users can use action=mcrundo to


replace the content of arbitrary pages.


(T297322, CVE-2021-44858) Unauthorized users can view contents of private


wikis using various actions.


(T297574, CVE-2021-45038) Unauthorized users can access private wiki


contents using rollback action


(T293589, CVE-2021-44855) Blind Stored XSS in VisualEditor media dialog.


(T294686) Special:Nuke doesn't actually delete pages.




Solution(s)

freebsd-upgrade-package-mediawiki135freebsd-upgrade-package-mediawiki136freebsd-upgrade-package-mediawiki137
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.