CVE-2014-8762: Infoleak
Published Oct 22, 2014
·Updated
The ajaxmediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a crafted namespace in the ns parameter.
Affected Software
1 affected component
DokuWiki DokuWiki<=2013-12-08
Event History
Oct 22, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8762?
CVE-2014-8762 has a medium severity rating due to its potential for remote unauthorized access to sensitive images.
2
How do I fix CVE-2014-8762?
To fix CVE-2014-8762, update DokuWiki to the latest version released after 2014-05-05a.
3
Which versions of DokuWiki are affected by CVE-2014-8762?
DokuWiki versions before 2014-05-05a are affected by CVE-2014-8762.
4
What is the impact of CVE-2014-8762?
CVE-2014-8762 allows remote attackers to access arbitrary images, potentially exposing sensitive information.
5
Is there a workaround for CVE-2014-8762 if I cannot update?
If an update cannot be performed, consider restricting access to the DokuWiki installation to trusted users only.