CVE Vulnerabilities

CVE-2021-30152

Improper Privilege Management

Published: Apr 09, 2021 | Modified: Nov 07, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
5.4 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM

An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to protect a page, a user is currently able to protect to a higher level than they currently have permissions for.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki * 1.31.13 (excluding)
Mediawiki Mediawiki 1.32.0 (including) 1.35.2 (excluding)
Mediawiki Ubuntu bionic *
Mediawiki Ubuntu devel *
Mediawiki Ubuntu esm-apps/bionic *
Mediawiki Ubuntu esm-apps/focal *
Mediawiki Ubuntu esm-apps/jammy *
Mediawiki Ubuntu esm-apps/noble *
Mediawiki Ubuntu focal *
Mediawiki Ubuntu groovy *
Mediawiki Ubuntu hirsute *
Mediawiki Ubuntu impish *
Mediawiki Ubuntu jammy *
Mediawiki Ubuntu kinetic *
Mediawiki Ubuntu lunar *
Mediawiki Ubuntu mantic *
Mediawiki Ubuntu noble *
Mediawiki Ubuntu trusty *
Mediawiki Ubuntu upstream *

Potential Mitigations

References