BIT-mediawiki-2023-36674
Dashboard / Vulnerabilities / BIT-mediawiki-2023-36674
Summary:
Details: An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax.
References: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2UIVGYECQGTUC2LLPVCZBPDLCTOHL2F6/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CHRX6DSLAMVXCV2YMJEWOLTBEYSESE5/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DOAXEGYBOEM4JWB4J3BDH73NK2LCYC3O/, https://phabricator.wikimedia.org/T335612, https://nvd.nist.gov/vuln/detail/CVE-2023-36674
Affected packages
Package
Name: mediawiki
Purl: pkg:bitnami/mediawiki
Affected ranges
Type: SEMVER
Events:
