First published: Fri Mar 31 2023(Updated: )
An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mediawiki | <=1:1.31.16-1+deb10u2 | 1:1.31.16-1+deb10u6 1:1.35.11-1~deb11u1 1:1.35.13-1~deb11u1 1:1.39.4-1~deb12u1 1:1.39.5-1~deb12u1 1:1.39.5-1 |
MediaWiki MediaWiki | <1.35.10 | |
MediaWiki MediaWiki | >=1.36.0<1.38.6 | |
MediaWiki MediaWiki | >=1.39.0<1.39.3 | |
Fedoraproject Fedora | =37 | |
composer/mediawiki/core | <1.35.10 | 1.35.10 |
composer/mediawiki/core | >=1.38.0<1.38.6 | 1.38.6 |
composer/mediawiki/core | >=1.39.0<1.39.3 | 1.39.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29141 is a vulnerability in MediaWiki before versions 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3 that allows an auto-block to occur for an untrusted X-Forwarded-For header.
CVE-2023-29141 is considered critical with a severity score of 9.8 out of 10.
CVE-2023-29141 affects MediaWiki versions before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3, allowing an auto-block to occur for an untrusted X-Forwarded-For header.
To fix CVE-2023-29141 in MediaWiki, you should update your MediaWiki installation to version 1.35.10, 1.38.6, or 1.39.3 or later.
You can find more information about CVE-2023-29141 at the following references: - [MediaWiki Release Notes](https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/core/+/REL1_39/RELEASE-NOTES-1.39) - [Debian LTS Announcement](https://lists.debian.org/debian-lts-announce/2023/08/msg00029.html) - [Fedora Project Announcement](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ONWHGOBFD6CQAEGOP5O375XAP2N6RUHT/)