REDHAT-BUG-580418: CSRF
MediaWiki upstream has released: [1] http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-April/000090.html
latest, v.1.15.3 version, addressing one cross-site request forgery (CSRF) issue (from [1]):
"MediaWiki was found to be vulnerable to login CSRF. An attacker who controls a user account on the target wiki can force the victim to log in as the attacker, via a script on an external website. If the wiki is configured to allow user scripts, say with "$wgAllowUserJs = true" in LocalSettings.php, then the attacker can proceed to mount a phishing-style attack against the victim to obtain their password."
Upstream bug report: [2] https://bugzilla.wikimedia.org/showbug.cgi?id=23076
CVE Request (and reply): [3] http://www.openwall.com/lists/oss-security/2010/04/07/1 [4] http://www.openwall.com/lists/oss-security/2010/04/08/4
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-580418?
The severity of REDHAT-BUG-580418 is categorized as a cross-site request forgery (CSRF) vulnerability that can lead to unauthorized actions on behalf of authenticated users.
How do I fix REDHAT-BUG-580418?
To fix REDHAT-BUG-580418, you should upgrade to the latest version of MediaWiki, specifically version 1.15.3 or later.
What systems are affected by REDHAT-BUG-580418?
REDHAT-BUG-580418 affects instances of Wikimedia MediaWiki running versions prior to 1.15.3.
When was REDHAT-BUG-580418 disclosed?
REDHAT-BUG-580418 was disclosed in April 2010.
What types of exploits are possible with REDHAT-BUG-580418?
Exploiting REDHAT-BUG-580418 could allow an attacker to perform actions on behalf of legitimate users without their consent.