Bug 1826079 (CVE-2020-10959) - CVE-2020-10959 mediawiki: user content can redirect the logout button to different URL
Summary: CVE-2020-10959 mediawiki: user content can redirect the logout button to diff...
Keywords:
Status: NEW
Alias: CVE-2020-10959
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 1826080 1827452 1827453
Blocks: 1826082
TreeView+ depends on / blocked
 
Reported: 2020-04-20 20:03 UTC by Guilherme de Almeida Suckevicz
Modified: 2023-07-07 08:29 UTC (History)
8 users (show)

Fixed In Version: mediawiki-1.34.0
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2020-04-20 20:03:48 UTC
User content can redirect the logout button to different URL.

Reference:
https://phabricator.wikimedia.org/T232932

Comment 1 Guilherme de Almeida Suckevicz 2020-04-20 20:04:05 UTC
Created mediawiki tracking bugs for this issue:

Affects: fedora-all [bug 1826080]

Comment 2 Jason Shepherd 2020-04-21 05:57:25 UTC
Release nodes:
https://lists.wikimedia.org/pipermail/wikitech-l/2020-March/093243.html

Comment 3 Jason Shepherd 2020-04-24 00:14:15 UTC
Statement:

The MediaWiki Ansible playbook has been removed from OpenShift Container Platform in version 4.3 and later.


Note You need to log in before you can comment on or make changes to this bug.