CVE-2019-12472: High severity mediawiki vulnerability
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Other sources
Forbid blocking IP ranges as big as /1 and /2, as done on ruwikiquote using the API
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12472?
CVE-2019-12472 has been classified with an incorrect access control vulnerability that allows IP range block limits to be bypassed.
How do I fix CVE-2019-12472?
To address CVE-2019-12472, upgrade to MediaWiki versions 1.32.2, 1.31.2, 1.30.2, or 1.27.6.
Which versions of MediaWiki are affected by CVE-2019-12472?
MediaWiki versions 1.18.0 through 1.32.1 are affected by CVE-2019-12472.
What kind of attack does CVE-2019-12472 allow?
CVE-2019-12472 allows attackers to bypass IP range blocks set by the API, potentially enabling unauthorized access.
Is it necessary to update all MediaWiki installations due to CVE-2019-12472?
Yes, it is essential to update all affected MediaWiki installations to mitigate the risks posed by CVE-2019-12472.