Bug 556494 (CVE-2010-0287, CVE-2010-0288, CVE-2010-0289)

Summary: CVE-2010-0287 CVE-2010-0288 CVE-2010-0289 dokuwiki: multiple vulnerabilities in ACL manager
Product: [Other] Security Response Reporter: Vincent Danen <vdanen>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: andrew
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2010-12-23 13:19:42 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 556496    
Bug Blocks:    

Description Vincent Danen 2010-01-18 15:47:59 UTC
The DokuWiki BTS [1] identified another security vulnerability in the ACL manager.  The plugin does not check against cross-site request forgeries (CSRF) which can be exploited to, for example, change access control rules by tricking a logged-in administrator into visiting a malicious website.

DokuWiki version 2009-12-25c was released to correct this vulnerability [2].

[1] http://bugs.splitbrain.org/index.php?do=details&task_id=1853
[2] http://www.splitbrain.org/_media/projects/dokuwiki/dokuwiki-2009-12-25c.tgz

Comment 3 Fedora Update System 2010-01-19 11:16:36 UTC
dokuwiki-0-0.4.20091225.c.el5 has been submitted as an update for Fedora EPEL 5.
http://admin.fedoraproject.org/updates/dokuwiki-0-0.4.20091225.c.el5

Comment 4 Fedora Update System 2010-01-19 11:16:45 UTC
dokuwiki-0-0.4.20091225.c.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/dokuwiki-0-0.4.20091225.c.fc12

Comment 5 Fedora Update System 2010-01-19 11:16:54 UTC
dokuwiki-0-0.4.20091225.c.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/dokuwiki-0-0.4.20091225.c.fc11

Comment 6 Tomas Hoger 2010-01-19 14:03:47 UTC
Reading the upstream bugs and upstream blog post, CSRF is actually less important of the issues.

Original report:
http://bugs.splitbrain.org/index.php?do=details&task_id=1847
http://secunia.com/advisories/38183/
- directory structure information leak
- insufficient permissions checks, allowing attacker to change ACLs

Follow-up report:
http://bugs.splitbrain.org/index.php?do=details&task_id=1853
http://secunia.com/advisories/38205/
- missing CSRF protections in ACL manager

Comment 8 Fedora Update System 2010-02-04 20:43:30 UTC
dokuwiki-0-0.4.20091225.c.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2010-02-05 01:22:34 UTC
dokuwiki-0-0.4.20091225.c.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 10 Fedora Update System 2010-02-05 01:49:50 UTC
dokuwiki-0-0.4.20091225.c.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.