LWN.net Logo

mediawiki: information leak

Package(s):mediawiki CVE #(s):CVE-2013-4302
Created:September 13, 2013 Updated:September 23, 2013
Description:

From the Debian advisory:

It was discovered that in Mediawiki, a wiki engine, several API modules allowed anti-CSRF tokens to be accessed via JSONP. These tokens protect against cross site request forgeries and are confidential.

Alerts:
Debian DSA-2753-1 2013-09-13
Mandriva MDVSA-2013:235 2013-09-16
Mageia MGASA-2013-0276 2013-09-13
Fedora FEDORA-2013-15994 2013-09-20
Fedora FEDORA-2013-15984 2013-09-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds