CVE-2024-23179: XSS
Published Jan 12, 2024
·Updated
An issue was discovered in the GlobalBlocking extension in MediaWiki before 1.40.2. For a Special:GlobalBlock?uselang=x-xss URI, i18n-based XSS can occur via the parentheses message. This affects subtitle links in buildSubtitleLinks.
Affected Software
1 affected component
MediaWiki MediaWiki<1.40.2
Remediation
Patch Available
Event History
Jan 12, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23179?
CVE-2024-23179 has a moderate severity level due to the potential for exploitation through XSS vulnerabilities.
2
How do I fix CVE-2024-23179?
To fix CVE-2024-23179, update MediaWiki to version 1.40.2 or later.
3
What specific issue does CVE-2024-23179 address?
CVE-2024-23179 addresses i18n-based XSS vulnerabilities in the GlobalBlocking extension for specific URIs.
4
Which versions of MediaWiki are affected by CVE-2024-23179?
CVE-2024-23179 affects all MediaWiki versions before 1.40.2.
5
What component of MediaWiki does CVE-2024-23179 impact?
CVE-2024-23179 impacts the GlobalBlocking extension within MediaWiki.