CVE-2020-29007: Code Injection
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted {{Image data to generate musical scores containing malicious code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-29007?
CVE-2020-29007 is a remote code execution vulnerability in the Score extension for MediaWiki.
How severe is CVE-2020-29007?
CVE-2020-29007 has a severity rating of 9.8 (critical).
What software is affected by CVE-2020-29007?
The Score extension through version 0.3.0 for MediaWiki is affected by CVE-2020-29007.
How can I fix CVE-2020-29007?
To fix CVE-2020-29007, update the Score extension for MediaWiki to a version beyond 0.3.0.
Where can I find more information about CVE-2020-29007?
You can find more information about CVE-2020-29007 on GitHub, Phabricator, and Seqred's website.