Information disclosure in MediaWiki - CVE-2010-2787
Published: April 27, 2011 / Updated: August 11, 2020
MediaWiki
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.
How to mitigate CVE-2010-2787
Sources
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058588.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059232.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059235.html
- http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-July/000092.html
- http://openwall.com/lists/oss-security/2010/07/29/4
- http://svn.wikimedia.org/viewvc/mediawiki?view=revision&revision=69776
- http://www.securityfocus.com/bid/42019
- https://bugzilla.redhat.com/show_bug.cgi?id=620224
- https://bugzilla.redhat.com/show_bug.cgi?id=620226
- https://bugzilla.wikimedia.org/show_bug.cgi?id=24565