CVE-2013-4572: High severity mediawiki vulnerability
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4572?
CVE-2013-4572 is categorized as a medium severity vulnerability due to its potential to allow unauthorized user authentication.
How do I fix CVE-2013-4572?
To fix CVE-2013-4572, upgrade to MediaWiki version 1.19.9, 1.20.8, or 1.21.3 or later.
What software is affected by CVE-2013-4572?
CVE-2013-4572 affects MediaWiki versions before 1.19.9, all 1.20.x versions before 1.20.8, and all 1.21.x versions before 1.21.3 as well as Fedora versions 18 and 19.
What exploit is possible with CVE-2013-4572?
CVE-2013-4572 allows remote attackers to authenticate as autocreated users due to the misconfigured Cache-Control header.
Which versions of MediaWiki are vulnerable to CVE-2013-4572?
MediaWiki versions prior to 1.19.9, 1.20.x versions before 1.20.8, and 1.21.x versions before 1.21.3 are vulnerable to CVE-2013-4572.