First published: Sun Sep 09 2012(Updated: )
The resource loader in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 includes private data such as CSRF tokens in a JavaScript file, which allows remote attackers to obtain sensitive information.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MediaWiki | =1.17 | |
MediaWiki MediaWiki | =1.17-beta_1 | |
MediaWiki MediaWiki | =1.17.0 | |
MediaWiki MediaWiki | =1.17.0-rc1 | |
MediaWiki MediaWiki | =1.17.1 | |
MediaWiki MediaWiki | =1.17.2 | |
MediaWiki MediaWiki | =1.18 | |
MediaWiki MediaWiki | =1.18-beta_1 | |
MediaWiki MediaWiki | =1.18.0 | |
MediaWiki MediaWiki | =1.18.0-rc1 | |
MediaWiki MediaWiki | =1.18.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.