CVE-2021-30158: Medium severity mediawiki vulnerability
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been compromised, and yet is not able to block any potential future use of the token by an unauthorized party.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-30158?
CVE-2021-30158 has a security relevance as it affects the ability of blocked users to reset tokens.
How do I fix CVE-2021-30158?
To fix CVE-2021-30158, upgrade MediaWiki to version 1.31.12 or 1.35.2 or later.
What versions of MediaWiki are affected by CVE-2021-30158?
CVE-2021-30158 affects MediaWiki versions before 1.31.12 and from 1.32.0 up to but not including 1.35.2.
Is CVE-2021-30158 a critical vulnerability?
CVE-2021-30158 may not be classified as critical, but it poses a risk related to token compromise for blocked users.
Who is affected by CVE-2021-30158?
CVE-2021-30158 affects users of MediaWiki who have been blocked from using Special:ResetTokens.