CVE-2011-4360: Infoleak
An information disclosure flaw was found in the way MediaWiki, the wiki engine, processed 'curid' and 'oldid' request paramaters. A remote attacker could use this flaw to enumerate page titles on private MediaWiki installations.
Upstream bug report: [1] https://bugzilla.wikimedia.org/showbug.cgi?id=32276
An information disclosure flaw was found in the way MediaWiki, the wiki engine, performed action=ajax requests dispatching to relevant internal functions. These requests were dispatched without any read permissions checks being done. A remote attacker could use this flaw to obtain data on private MediaWiki installations.
Upstream bug report: [2] https://bugzilla.wikimedia.org/showbug.cgi?id=32616
References: [3] http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-November/000104.html [4] http://www.openwall.com/lists/oss-security/2011/11/29/6 [5] https://bugs.gentoo.org/showbug.cgi?id=392383
Upstream patch (covering both of the issues): [6] http://www.mediawiki.org/wiki/Special:Code/MediaWiki/104506
Other sources
MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4360?
CVE-2011-4360 has a moderate severity rating, allowing information disclosure on private MediaWiki installations.
How do I fix CVE-2011-4360?
To fix CVE-2011-4360, upgrade to MediaWiki version 1.17.1 or later to patch the vulnerability.
What kind of attack can exploit CVE-2011-4360?
CVE-2011-4360 can be exploited by remote attackers to enumerate private page titles through crafted 'curid' and 'oldid' parameters.
Which versions of MediaWiki are affected by CVE-2011-4360?
MediaWiki versions prior to 1.17.1 are vulnerable to CVE-2011-4360.
Is there a specific operating system affected by CVE-2011-4360?
Yes, CVE-2011-4360 affects installations of MediaWiki on Debian GNU/Linux versions 5.0 and 6.0.