Search CVE reports


Toggle filters

171 – 180 of 332 results


CVE-2019-12470

Medium priority

Some fixes available 14 of 17

Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

1 affected package

mediawiki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Fixed Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2019-12469

Medium priority

Some fixes available 14 of 17

MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

1 affected package

mediawiki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Fixed Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2019-12474

Medium priority

Some fixes available 14 of 17

Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

1 affected package

mediawiki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Fixed Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2019-12473

Medium priority

Some fixes available 14 of 17

Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

1 affected package

mediawiki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Fixed Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2019-12472

Medium priority

Some fixes available 14 of 17

An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

1 affected package

mediawiki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Fixed Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2019-12471

Medium priority

Some fixes available 14 of 17

Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

1 affected package

mediawiki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Fixed Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2019-12466

Medium priority

Some fixes available 14 of 17

Wikimedia MediaWiki through 1.32.1 allows CSRF.

1 affected package

mediawiki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Fixed Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2019-12468

Medium priority

Some fixes available 14 of 17

An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.

1 affected package

mediawiki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Fixed Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2019-12467

Low priority

Some fixes available 14 of 17

MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

1 affected package

mediawiki

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mediawiki Fixed Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2019-11358

Low priority

Some fixes available 3 of 28

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property,...

5 affected packages

drupal7, jquery, node-jquery, mediawiki, otrs2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
drupal7 Not in release Not in release Not in release Not in release Not in release
jquery Not in release Not in release Not in release Not affected Fixed
node-jquery Not affected Not affected Not affected Not affected Vulnerable
mediawiki Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
otrs2 Not in release Not in release Needs evaluation Not affected Needs evaluation
Show less packages