CVE-2021-30155: Medium severity mediawiki vulnerability
Published Apr 9, 2021
·Updated
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not check if a user has correct permissions to create and set the content model of a nonexistent page.
Affected Software
7 affected componentsFixes available
debian/mediawiki
1:1.31.16-1+deb10u21:1.31.16-1+deb10u61:1.35.11-1~deb11u11:1.35.13-1~deb11u11:1.39.4-1~deb12u11:1.39.5-1~deb12u11:1.39.5-1
MediaWiki MediaWiki<1.31.12
MediaWiki MediaWiki>=1.32.0<1.35.2
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Remediation
Patch Available
Event History
Apr 9, 2021
CVE Published
via MITRE·06:09 AM
Data Sourced
via MITRE·06:09 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-30155?
CVE-2021-30155 has been classified as a medium severity vulnerability due to improper permission checks.
2
How do I fix CVE-2021-30155?
To fix CVE-2021-30155, update MediaWiki to versions 1.31.16, 1.35.2, or later.
3
Which versions of MediaWiki are affected by CVE-2021-30155?
CVE-2021-30155 affects MediaWiki versions before 1.31.12 and between 1.32.0 and 1.35.2.
4
What kind of attack can exploit CVE-2021-30155?
An attacker can exploit CVE-2021-30155 by creating and setting the content model of a nonexistent page if they lack appropriate permissions.
5
Is CVE-2021-30155 related to Debian or Fedora systems?
Yes, CVE-2021-30155 affects MediaWiki installations on Debian and Fedora systems.