First published: Thu Feb 06 2020(Updated: )
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wikimedia MediaWiki | <1.19.9 | |
Wikimedia MediaWiki | >=1.20<1.20.8 | |
Wikimedia MediaWiki | >=1.21<1.21.3 | |
Fedora | =18 | |
Fedora | =19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4572 is categorized as a medium severity vulnerability due to its potential to allow unauthorized user authentication.
To fix CVE-2013-4572, upgrade to MediaWiki version 1.19.9, 1.20.8, or 1.21.3 or later.
CVE-2013-4572 affects MediaWiki versions before 1.19.9, all 1.20.x versions before 1.20.8, and all 1.21.x versions before 1.21.3 as well as Fedora versions 18 and 19.
CVE-2013-4572 allows remote attackers to authenticate as autocreated users due to the misconfigured Cache-Control header.
MediaWiki versions prior to 1.19.9, 1.20.x versions before 1.20.8, and 1.21.x versions before 1.21.3 are vulnerable to CVE-2013-4572.