CVE-2012-4382: Infoleak
Published Oct 19, 2017
·Updated
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not properly protect user block metadata, which allows remote administrators to read a user block reason via a reblock attempt.
Affected Software
4 affected componentsFixes available
debian/mediawiki
1:1.31.16-1+deb10u21:1.31.16-1+deb10u61:1.35.11-1~deb11u11:1.35.13-1~deb11u11:1.39.4-1~deb12u11:1.39.5-1~deb12u11:1.39.5-1
MediaWiki MediaWiki<=1.18.4
MediaWiki MediaWiki=1.19.0
MediaWiki MediaWiki=1.19.1
Remediation
Patch Available
Patch Available
Event History
Oct 19, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4382?
CVE-2012-4382 has a medium severity level due to the potential exposure of sensitive user block metadata.
2
How do I fix CVE-2012-4382?
To fix CVE-2012-4382, update to MediaWiki versions 1.18.5, 1.19.2 or later.
3
Which versions of MediaWiki are affected by CVE-2012-4382?
MediaWiki versions before 1.18.5 and 1.19.x before 1.19.2 are affected by CVE-2012-4382.
4
Can remote administrators exploit CVE-2012-4382?
Yes, remote administrators can exploit CVE-2012-4382 to read user block reasons through reblock attempts.
5
Is there a workaround for CVE-2012-4382 if I cannot update?
There is no official workaround for CVE-2012-4382, so upgrading to a patched version is recommended.