|
|
Subscribe / Log in / New account

mediawiki: multiple vulnerabilities

Package(s):mediawiki CVE #(s):CVE-2010-1189 CVE-2010-1190
Created:July 6, 2010 Updated:July 7, 2010
Description: From the Fedora advisory:

Three security issues are fixed in this update: A CSS validation issue was discovered which allows editors to display external images in wiki pages. A data leakage vulnerability was discovered in thumb.php which affects wikis which restrict access to private files using img_auth.php, or some similar scheme. MediaWiki was found to be vulnerable to login CSRF. The upstream authors recommend that all public wikis should be upgraded if possible. The fix includes a breaking change to the API login action. Any clients using it will need to be updated.

Alerts:
Fedora FEDORA-2010-6335 mediawiki 2010-04-10

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds