CVE Vulnerabilities

CVE-2023-36674

Published: Aug 20, 2023 | Modified: Nov 07, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
MEDIUM

An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki * 1.35.11 (excluding)
Mediawiki Mediawiki 1.36.0 (including) 1.38.7 (excluding)
Mediawiki Mediawiki 1.39.0 (including) 1.39.4 (excluding)
Mediawiki Mediawiki 1.40.0 (including) 1.40.0 (including)
Mediawiki Ubuntu bionic *
Mediawiki Ubuntu kinetic *
Mediawiki Ubuntu lunar *
Mediawiki Ubuntu trusty *
Mediawiki Ubuntu upstream *
Mediawiki Ubuntu xenial *

References