Description
In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2779-1 | mediawiki security update |
Debian DSA |
DSA-4979-1 | mediawiki security update |
EUVD |
EUVD-2021-21841 | In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented). |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T00:33:51.175Z
Reserved: 2021-06-22T00:00:00.000Z
Link: CVE-2021-35197
No data.
Status : Modified
Published: 2021-07-02T13:15:07.727
Modified: 2024-11-21T06:12:01.660
Link: CVE-2021-35197
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD