REDHAT-BUG-620224: CSRF
Tim Starling reported: [1] https://bugzilla.wikimedia.org/showbug.cgi?id=24565#c0
a deficiency in the way MediaWiki processed private cache headers for almost all API operations. Further exact flaw implications from Tim [1]:
A user's browser can be tricked into requesting private data with public caching headers, via a CSRF-style attack on an external web page. The attacker would cause the victim's browser to request private data with public caching headers, then the attacker would download the same data from the intermediate HTTP proxy, bypassing access controls.
References: [2] http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-July/000092.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-620224?
REDHAT-BUG-620224 is considered to have a significant impact due to improper handling of private cache headers in MediaWiki.
How do I fix REDHAT-BUG-620224?
To fix REDHAT-BUG-620224, apply the recommended patches for the affected version of MediaWiki as released by the developers.
What software is affected by REDHAT-BUG-620224?
REDHAT-BUG-620224 affects Wikimedia MediaWiki installations, particularly those utilizing API operations.
What are the implications of REDHAT-BUG-620224?
The implications of REDHAT-BUG-620224 include potential leaks of private data due to inadequate cache header processing.
Who reported REDHAT-BUG-620224?
REDHAT-BUG-620224 was reported by Tim Starling, highlighting a vulnerability in MediaWiki's cache handling.