First published: Thu Mar 12 2020(Updated: )
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an IP address is contained in two ranges, one of which is locally disabled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki | <=1.34.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10534 has a high severity rating due to the potential for blocked users to regain escalated privileges.
You can fix CVE-2020-10534 by updating your MediaWiki installation to version 1.34.1 or later.
MediaWiki versions up to and including 1.34.0 are affected by CVE-2020-10534.
CVE-2020-10534 is a privilege escalation vulnerability related to IP range evaluation.
Yes, CVE-2020-10534 can compromise user security by allowing unauthorized access to blocked users.