First published: Thu Oct 19 2017(Updated: )
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not properly protect user block metadata, which allows remote administrators to read a user block reason via a reblock attempt.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mediawiki | 1:1.31.16-1+deb10u2 1:1.31.16-1+deb10u6 1:1.35.11-1~deb11u1 1:1.35.13-1~deb11u1 1:1.39.4-1~deb12u1 1:1.39.5-1~deb12u1 1:1.39.5-1 | |
Wikimedia MediaWiki | <=1.18.4 | |
Wikimedia MediaWiki | =1.19.0 | |
Wikimedia MediaWiki | =1.19.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4382 has a medium severity level due to the potential exposure of sensitive user block metadata.
To fix CVE-2012-4382, update to MediaWiki versions 1.18.5, 1.19.2 or later.
MediaWiki versions before 1.18.5 and 1.19.x before 1.19.2 are affected by CVE-2012-4382.
Yes, remote administrators can exploit CVE-2012-4382 to read user block reasons through reblock attempts.
There is no official workaround for CVE-2012-4382, so upgrading to a patched version is recommended.