First published: Fri Dec 13 2013(Updated: )
Cross-site request forgery (CSRF) vulnerability in the CentralAuth extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to hijack the authentication of users for requests that login via vectors involving image loading.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wikimedia MediaWiki | =1.20 | |
Wikimedia MediaWiki | =1.20.1 | |
Wikimedia MediaWiki | =1.20.2 | |
Wikimedia MediaWiki | =1.20.3 | |
Wikimedia MediaWiki | =1.20.4 | |
Wikimedia MediaWiki | =1.20.5 | |
Wikimedia MediaWiki | =1.20.6 | |
Wikimedia MediaWiki | =1.20.7 | |
Wikimedia MediaWiki | =1.21 | |
Wikimedia MediaWiki | =1.21.1 | |
Wikimedia MediaWiki | =1.21.2 | |
Wikimedia MediaWiki | <=1.19.8 | |
Wikimedia MediaWiki | =1.19 | |
Wikimedia MediaWiki | =1.19-beta_1 | |
Wikimedia MediaWiki | =1.19-beta_2 | |
Wikimedia MediaWiki | =1.19.0 | |
Wikimedia MediaWiki | =1.19.1 | |
Wikimedia MediaWiki | =1.19.2 | |
Wikimedia MediaWiki | =1.19.3 | |
Wikimedia MediaWiki | =1.19.4 | |
Wikimedia MediaWiki | =1.19.5 | |
Wikimedia MediaWiki | =1.19.6 | |
Wikimedia MediaWiki | =1.19.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5394 is classified as a moderate severity cross-site request forgery (CSRF) vulnerability.
To fix CVE-2012-5394, upgrade MediaWiki to version 1.19.9, 1.20.8, or 1.21.3 or later.
CVE-2012-5394 affects MediaWiki versions before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3.
CVE-2012-5394 allows remote attackers to hijack user authentication through CSRF attacks involving image loading vectors.
Users of the affected MediaWiki versions who rely on CentralAuth are at risk of being attacked via CVE-2012-5394.