SB2020020622 - Session Fixation in MediaWiki MediaWiki



SB2020020622 - Session Fixation in MediaWiki MediaWiki

Published: February 6, 2020 Updated: July 17, 2020

Security Bulletin ID SB2020020622
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Session Fixation (CVE-ID: CVE-2013-4572)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.


Remediation

Install update from vendor's website.