CVE Vulnerabilities

CVE-2019-12472

Published: Jul 10, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki 1.18.0 (including) 1.27.6 (excluding)
Mediawiki Mediawiki 1.30.0 (including) 1.30.2 (excluding)
Mediawiki Mediawiki 1.31.0 (including) 1.31.2 (excluding)
Mediawiki Mediawiki 1.32.0 (including) 1.32.2 (excluding)
Mediawiki Ubuntu bionic *
Mediawiki Ubuntu cosmic *
Mediawiki Ubuntu devel *
Mediawiki Ubuntu disco *
Mediawiki Ubuntu eoan *
Mediawiki Ubuntu esm-apps/bionic *
Mediawiki Ubuntu focal *
Mediawiki Ubuntu groovy *
Mediawiki Ubuntu hirsute *
Mediawiki Ubuntu impish *
Mediawiki Ubuntu jammy *
Mediawiki Ubuntu kinetic *
Mediawiki Ubuntu lunar *
Mediawiki Ubuntu mantic *
Mediawiki Ubuntu noble *
Mediawiki Ubuntu oracular *
Mediawiki Ubuntu trusty *
Mediawiki Ubuntu upstream *

References