CVE-2022-29906: Critical severity mediawiki vulnerability
Published Apr 29, 2022
·Updated
The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user.
Affected Software
1 affected component
MediaWiki MediaWiki<=1.37.2
Remediation
Patch Available
Event History
Apr 29, 2022
CVE Published
via MITRE·03:42 AM
Data Sourced
via MITRE·03:42 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-29906?
The severity of CVE-2022-29906 is classified as medium due to the potential unauthorized access to admin functions.
2
How do I fix CVE-2022-29906?
To fix CVE-2022-29906, upgrade to MediaWiki version 1.37.3 or later where the vulnerability has been patched.
3
Which versions of MediaWiki are affected by CVE-2022-29906?
CVE-2022-29906 affects MediaWiki versions up to and including 1.37.2.
4
What does CVE-2022-29906 exploit in the QuizGame extension?
CVE-2022-29906 exploits a lack of user checks in the admin API module of the QuizGame extension.
5
Is my MediaWiki installation safe from CVE-2022-29906 if I am running version 1.37.3 or newer?
Yes, if you are running MediaWiki version 1.37.3 or newer, your installation is safe from CVE-2022-29906.