CVE-2017-0370: Spam blacklist ineffective on encoded URLs inside file inclusion syntax's link parameter
Published Apr 13, 2018
·Updated
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.
Affected Software
5 affected componentsFixes available
MediaWiki MediaWiki>=1.23.0<=1.23.16
MediaWiki MediaWiki>=1.27.0<1.27.2
MediaWiki MediaWiki>=1.28.0<1.28.1
Debian Debian Linux=7.0
debian/mediawiki
1:1.35.13-1+deb11u21:1.35.13-1+deb11u61:1.39.17-1~deb12u11:1.43.6+dfsg-1~deb13u11:1.43.6+dfsg-2
Event History
Apr 13, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Feb 19, 2026
Data Sourced
via Debian·07:26 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-0370?
CVE-2017-0370 is a medium-severity vulnerability affecting MediaWiki versions before 1.28.1, 1.27.2, and 1.23.16.
2
How do I fix CVE-2017-0370?
To fix CVE-2017-0370, update your MediaWiki to the latest versions: 1.35.13-1+deb11u2, 1.39.7-1~deb12u1, or 1.39.8.
3
Which versions of MediaWiki are affected by CVE-2017-0370?
CVE-2017-0370 affects MediaWiki versions from 1.23.0 to below 1.28.1, as well as 1.27.0 to below 1.27.2, and 1.28.0 to below 1.28.1.
4
What type of vulnerability is CVE-2017-0370?
CVE-2017-0370 is a file inclusion vulnerability that allows encoded URLs to bypass the spam blacklist in MediaWiki.
5
Is there a workaround for CVE-2017-0370?
There is no known workaround for CVE-2017-0370; upgrading to a patched version is the recommended action.