CVE-2021-30152: Medium severity mediawiki vulnerability
An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently have permissions for.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-30152?
CVE-2021-30152 is a vulnerability in MediaWiki that allows users to protect a page to a higher level than their permissions allow.
What is the severity of CVE-2021-30152?
The severity of CVE-2021-30152 is not specified.
How does CVE-2021-30152 affect MediaWiki?
CVE-2021-30152 allows users to protect a page to a higher level than their permissions allow in MediaWiki.
How do I fix CVE-2021-30152 in MediaWiki?
To fix CVE-2021-30152 in MediaWiki, update to version 1.31.13 or later for 1.31.x, or update to version 1.35.2 or later for 1.32.x through 1.35.x.
Where can I find more information about CVE-2021-30152?
You can find more information about CVE-2021-30152 on the following references: [Phabricator](https://phabricator.wikimedia.org/T270713), [Wikitech-l Mailing List](https://lists.wikimedia.org/pipermail/wikitech-l/2021-April/094418.html), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2021-30152).