An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are created with file mode 0644, i.e., world readable to local users. These files include credentials data.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mediawiki | Mediawiki | * | 1.35.9 (excluding) |
Mediawiki | Mediawiki | 1.36.0 (including) | 1.38.5 (excluding) |
Mediawiki | Mediawiki | 1.39.0 (including) | 1.39.0 (including) |
Mediawiki | Mediawiki | 1.39.0-rc0 (including) | 1.39.0-rc0 (including) |
Mediawiki | Mediawiki | 1.39.0-rc1 (including) | 1.39.0-rc1 (including) |
Mediawiki | Ubuntu | bionic | * |
Mediawiki | Ubuntu | kinetic | * |
Mediawiki | Ubuntu | trusty | * |
Mediawiki | Ubuntu | upstream | * |
Mediawiki | Ubuntu | xenial | * |