First published: Tue Apr 06 2021(Updated: )
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been compromised, and yet is not able to block any potential future use of the token by an unauthorized party.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mediawiki | 1:1.31.16-1+deb10u2 1:1.31.16-1+deb10u6 1:1.35.11-1~deb11u1 1:1.35.13-1~deb11u1 1:1.39.4-1~deb12u1 1:1.39.5-1~deb12u1 1:1.39.5-1 | |
Wikimedia MediaWiki | <1.31.12 | |
Wikimedia MediaWiki | >=1.32.0<1.35.2 | |
Debian GNU/Linux | =9.0 | |
Debian GNU/Linux | =10.0 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-30158 has a security relevance as it affects the ability of blocked users to reset tokens.
To fix CVE-2021-30158, upgrade MediaWiki to version 1.31.12 or 1.35.2 or later.
CVE-2021-30158 affects MediaWiki versions before 1.31.12 and from 1.32.0 up to but not including 1.35.2.
CVE-2021-30158 may not be classified as critical, but it poses a risk related to token compromise for blocked users.
CVE-2021-30158 affects users of MediaWiki who have been blocked from using Special:ResetTokens.