CVE Vulnerabilities

CVE-2019-12467

Published: Jul 10, 2019 | Modified: Aug 24, 2020
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki * 1.27.6 (excluding)
Mediawiki Mediawiki 1.30.0 (including) 1.30.2 (excluding)
Mediawiki Mediawiki 1.31.0 (including) 1.31.2 (excluding)
Mediawiki Mediawiki 1.32.0 (including) 1.32.2 (excluding)
Mediawiki Ubuntu bionic *
Mediawiki Ubuntu cosmic *
Mediawiki Ubuntu devel *
Mediawiki Ubuntu disco *
Mediawiki Ubuntu eoan *
Mediawiki Ubuntu esm-apps/bionic *
Mediawiki Ubuntu focal *
Mediawiki Ubuntu groovy *
Mediawiki Ubuntu hirsute *
Mediawiki Ubuntu impish *
Mediawiki Ubuntu jammy *
Mediawiki Ubuntu kinetic *
Mediawiki Ubuntu lunar *
Mediawiki Ubuntu mantic *
Mediawiki Ubuntu noble *
Mediawiki Ubuntu oracular *
Mediawiki Ubuntu trusty *
Mediawiki Ubuntu upstream *

References