An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protected against "page creation" and the attacker should not be able to create it. This occurs because of a mishandled distinction between an upload restriction and a create restriction. An attacker cannot leverage this to overwrite anything, but can leverage this to force a wiki to have a page with a disallowed title. References: https://commons.wikimedia.org/w/index.php?oldid=454609892#File:Wiki.png https://gerrit.wikimedia.org/r/q/Ib852a96afc4dca10516d0510e69c10f9892b351b https://phabricator.wikimedia.org/T262628
Created mediawiki tracking bugs for this issue: Affects: fedora-all [bug 1903755]
The vulnerability is directly related to FileImporter Extension, which is not bundled in the OpenShift mediawiki package.
External References: https://phabricator.wikimedia.org/T262628
Statement: OpenShift Container Platform (OCP) delivers the mediawiki package, but the vulnerable code is not bundled, therefore OCP is not affected by this flaw.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-26121