Bug 1634161 (CVE-2018-0503)
Summary: | CVE-2018-0503 mediawiki: $wgRateLimits (rate limit / ping limiter) entry for 'user' overrides that for 'newbie' | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Pedro Sampaio <psampaio> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | ahardin, aos-bugs, Axel.Thimm, bleanhar, bmontgom, ccoleman, dedgar, eparis, gwync, jburrell, jgoulding, jokerman, mchappel, mike, nstielau, puiterwijk, shurley, sponnaga |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | mediawiki 1.31.1, mediawiki 1.30.1, mediawiki 1.29.3, mediawiki 1.27.5 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2019-10-18 06:51:19 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1634162, 1710098, 1734829, 1734830, 1742212, 1742213 | ||
Bug Blocks: | 1634171 |
Description
Pedro Sampaio
2018-09-28 20:27:04 UTC
Created mediawiki tracking bugs for this issue: Affects: fedora-all [bug 1634162] Updating affected products; mediawiki-123 is the container name, mediawiki123 is the package name. I'm not sure why I didn't file bugs against 3.9 and 3.10 earlier. I confirmed the latest tagged containers are still affected and am filing those trackers not. (3.6 and 3.7 went EOL, so those are just being marked as such) This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.11 Via RHSA-2019:3142 https://access.redhat.com/errata/RHSA-2019:3142 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2018-0503 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.10 Via RHSA-2019:3238 https://access.redhat.com/errata/RHSA-2019:3238 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.9 Via RHSA-2019:3813 https://access.redhat.com/errata/RHSA-2019:3813 |