|
|
Log in / Subscribe / Register

Debian alert DLA-4640-1 (mediawiki)

From:  Guilhem Moulin <guilhem@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4640-1] mediawiki security update
Date:  Mon, 22 Jun 2026 04:44:26 +0200
Message-ID:  <ajihiov-Zb_-8BEp@debian.org>

------------------------------------------------------------------------- Debian LTS Advisory DLA-4640-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Guilhem Moulin June 22, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : mediawiki Version : 1:1.35.13-1+deb11u7 $bookworm_VERSION CVE ID : CVE-2026-34087 CVE-2026-34088 CVE-2026-34093 CVE-2026-34095 Multiple security vulnerabilities were found in mediawiki, a website engine for collaborative work, which could lead to information disclosure or access controls bypass. CVE-2026-34087 OATHAuth extension: Users API leaks whether privileged users have their user groups disabled for lack of 2FA. CVE-2026-34088 RecentChanges entries expose suppressed content via generated log page HTML. CVE-2026-34093 Special:UserRights page allows viewing user rights from private wiki. CVE-2026-34095 action=raw with Special:Mypage subpage title responds with "Content-Type: text/html" on ctype=text/javascript request, which may lead to cross-site scripting. For Debian 11 bullseye, these problems have been fixed in version 1:1.35.13-1+deb11u7. For Debian 12 bookworm, these problems have been fixed in version $bookworm_VERSION. We recommend that you upgrade your mediawiki packages. For the detailed security status of mediawiki please refer to its security tracker page at: https://security-tracker.debian.org/tracker/mediawiki Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmo4oYoACgkQ05pJnDwh pVIviw//SqTJGsCyH/ro6LIR0JEgNjSSjVkkZvif/pUq2vkbDDQwWDjmYTgIKwvz h+whKOlZpIWHeWQHrHo5FdDuwqsrPvbJikGvEEPdPymxTi5U5LH8yffK0Wd9YTyf MEIqbwW2oq3ybRodBkAH/JJjLcFcGEEGlqCMiwbioi+UcHReY8kUoPdFGnP9zyQL 7U22y3e4xYlR68NjhD/tu2Tfl/vdA7i9kt50bofJ8OkoxdvYz1NWZ0Eg5OxfhP/F L+1gjU8+E9U08i/LGAO1Jr7+pw71vfgCaHevMA0VI8SHA2pcTFZ69Vt/YsB8fbBr Z0oRnG2q7SSvTBCeATtSIyZ6w9OHxRCBq6FLHyQNscjOt19BGp3dVtwRV5Fwl8JX b5DUT82IvvMB8FBNm8PQkDGk0NV6qGFUoUSzcOFXzK9fIzthQDoqfgAZYWXOSmcG SV5XUokUtDFBABOPI4bhr2lhN5PfqyctHgY3l84F+uYWGVBKvARVmY+bQVY0SQ/8 vPjEPqhPTis/2TpIu46G36J8dZVaNZcUUSPb8HEB7CgtCgGHhYdqff9/7oUOXpiS sEEMnmI1f5CkSN3pZmP2n9UUwOoPJ5n89Py0bxyY5Jq4DS/Fv9rpB/0OpjfQayw1 YhCJlbc0fbksIdFwP0uwpeHJuUZqjXeE4bDhjdctxyJSbN/O+no= =iJKM -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds