First published: Thu Oct 19 2017(Updated: )
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct clickjacking attacks via an embedded API response in an IFRAME element.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mediawiki | 1:1.31.16-1+deb10u2 1:1.31.16-1+deb10u6 1:1.35.11-1~deb11u1 1:1.35.13-1~deb11u1 1:1.39.4-1~deb12u1 1:1.39.5-1~deb12u1 1:1.39.5-1 | |
MediaWiki | <=1.18.4 | |
MediaWiki | =1.19.0 | |
MediaWiki | =1.19.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4379 is classified as a medium-severity vulnerability due to its potential for clickjacking attacks.
To fix CVE-2012-4379, update to MediaWiki version 1.18.5, 1.19.2, or later.
CVE-2012-4379 affects MediaWiki versions prior to 1.18.5 and 1.19.x versions before 1.19.2.
In the context of CVE-2012-4379, a clickjacking attack allows remote attackers to trick users into clicking on hidden elements in an embedded IFRAME.
Using MediaWiki versions older than 1.18.5 or 1.19.2 is not safe due to the risk of clickjacking attacks associated with CVE-2012-4379.