CVE-2017-8809: Critical severity mediawiki vulnerability
Published Nov 15, 2017
·Updated
api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.
Affected Software
8 affected componentsFixes available
debian/mediawiki
1:1.31.16-1+deb10u21:1.31.16-1+deb10u61:1.35.11-1~deb11u11:1.35.13-1~deb11u11:1.39.4-1~deb12u11:1.39.5-1~deb12u11:1.39.5-1
MediaWiki MediaWiki<=1.27.3
MediaWiki MediaWiki=1.28.0
MediaWiki MediaWiki=1.28.1
MediaWiki MediaWiki=1.28.2
MediaWiki MediaWiki=1.29.0
MediaWiki MediaWiki=1.29.1
Debian Debian Linux=9.0
Remediation
Event History
Nov 15, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-8809?
CVE-2017-8809 has a medium severity rating due to its Reflected File Download vulnerability.
2
How do I fix CVE-2017-8809?
To resolve CVE-2017-8809, update MediaWiki to version 1.27.4, 1.28.3, or 1.29.2 or later.
3
Which MediaWiki versions are affected by CVE-2017-8809?
CVE-2017-8809 affects MediaWiki versions up to 1.27.3 and specific versions including 1.28.0, 1.28.1, 1.28.2, 1.29.0, and 1.29.1.
4
Is CVE-2017-8809 still a risk for users of MediaWiki?
Yes, users of the affected MediaWiki versions remain at risk for CVE-2017-8809 if they have not upgraded.
5
What type of vulnerability is CVE-2017-8809?
CVE-2017-8809 is a Reflected File Download vulnerability that could potentially allow attackers to download arbitrary files.