CVE-2017-0367: Having LocalisationCache directory default to system tmp directory is insecure
Published Apr 13, 2018
·Updated
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.
Affected Software
4 affected componentsFixes available
MediaWiki MediaWiki>=1.27.0<1.27.2
MediaWiki MediaWiki>=1.28.0<1.28.1
Debian Debian Linux=7.0
debian/mediawiki
1:1.35.13-1+deb11u21:1.35.13-1+deb11u61:1.39.17-1~deb12u11:1.43.6+dfsg-1~deb13u11:1.43.6+dfsg-2
Event History
Apr 13, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Feb 19, 2026
Data Sourced
via Debian·07:26 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-0367?
CVE-2017-0367 is classified as having a moderate severity due to its impact on security related to file accessibility.
2
How do I fix CVE-2017-0367?
To remediate CVE-2017-0367, upgrade MediaWiki to version 1.28.1, 1.27.2, or later where the issue has been addressed.
3
Which versions of MediaWiki are affected by CVE-2017-0367?
CVE-2017-0367 affects MediaWiki versions prior to 1.28.1 and 1.27.2.
4
What is the nature of the vulnerability in CVE-2017-0367?
CVE-2017-0367 involves an insecure use of the temporary directory that could lead to local file exposure.
5
Is there a specific operating system affected by CVE-2017-0367?
Yes, this vulnerability can also affect Debian Linux 7.0 when using impacted versions of MediaWiki.