CVE-2014-2244: XSS
Cross-site scripting (XSS) vulnerability in the formatHTML function in includes/api/ApiFormatBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 allows remote attackers to inject arbitrary web script or HTML via a crafted string located after http:// in the text parameter to api.php.
Other sources
The MediaWiki 1.22.3, 1.21.6 and 1.19.12 release announcement notes:
(bug 61362) SECURITY: API: Don't find links in the middle of api.php links.
An attacker could perform cross-site scripting attacks.
The versions of MediaWiki in Fedora and EPEL 6 are affected. I have not tested EPEL 5.
References: http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-February/000141.html https://bugzilla.wikimedia.org/showbug.cgi?id=61362 https://gerrit.wikimedia.org/r/#/q/Idf985e4e69c2f11778a8a90503914678441cb3fb,n,z
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/mediawikito a version that resolves this vulnerability.Fixed in 1.22.3 - Upgrade
Upgrade
redhat/mediawikito a version that resolves this vulnerability.Fixed in 1.21.6 - Upgrade
Upgrade
redhat/mediawikito a version that resolves this vulnerability.Fixed in 1.19.13 - Upgrade
Upgrade
MediaWikito a version that resolves this vulnerability.Fixed in 1.19.12 - Upgrade
Upgrade
MediaWikito a version that resolves this vulnerability.Fixed in 1.21.6 - Upgrade
Upgrade
MediaWikito a version that resolves this vulnerability.Fixed in 1.22.3
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2244?
CVE-2014-2244 has a medium severity rating due to its potential to allow cross-site scripting attacks that can inject malicious scripts or HTML into web pages.
How do I fix CVE-2014-2244?
To fix CVE-2014-2244, upgrade MediaWiki to version 1.22.3, 1.21.6, or 1.19.13, as these versions address the vulnerability.
Which versions of MediaWiki are affected by CVE-2014-2244?
CVE-2014-2244 affects MediaWiki versions prior to 1.19.12, 1.20.x and 1.21.x before 1.21.6, as well as 1.22.x before 1.22.3.
What type of attack is possible with CVE-2014-2244?
CVE-2014-2244 allows remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML into pages viewed by users.
Who is impacted by CVE-2014-2244?
Users and administrators of MediaWiki versions prior to the specified patched versions are at risk of exploitation through this XSS vulnerability.