Exposure of Resource to Wrong Sphere in MediaWiki - CVE-2017-0367
Published: April 13, 2018 / Updated: July 17, 2020
Vulnerability identifier: #VU31325
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-0367
CWE-ID:
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to execute arbitrary code.
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.
Affected software
MediaWiki
Arch Linux
Fedora
mediawiki
Arch Linux
Fedora
mediawiki
How to mitigate CVE-2017-0367
Install update from vendor's website.
MediaWiki - update to 1.28.1
mediawiki - update to 1.27.2-1.fc25
mediawiki - update to 1.27.2-1.fc25