CVE-2013-6455: Infoleak
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6455?
CVE-2013-6455 is classified as a medium severity vulnerability that allows remote attackers to expose usernames.
How do I fix CVE-2013-6455?
To mitigate CVE-2013-6455, users should upgrade MediaWiki to version 1.19.10 or later, or versions 1.21.4 and 1.22.1.
What systems are affected by CVE-2013-6455?
CVE-2013-6455 affects MediaWiki versions before 1.19.10, 1.20.x before 1.21.4, and 1.22.x before 1.22.1.
What type of attack does CVE-2013-6455 involve?
CVE-2013-6455 involves a vulnerability that allows attackers to obtain usernames by manipulating the DOM of a page.
Is there a workaround for CVE-2013-6455?
There is no specific workaround recommended for CVE-2013-6455; upgrading is the best course of action.