Tim Starling reported: [1] https://bugzilla.wikimedia.org/show_bug.cgi?id=24565#c0 a deficiency in the way MediaWiki processed private cache headers for almost all API operations. Further exact flaw implications from Tim [1]: A user's browser can be tricked into requesting private data with public caching headers, via a CSRF-style attack on an external web page. The attacker would cause the victim's browser to request private data with public caching headers, then the attacker would download the same data from the intermediate HTTP proxy, bypassing access controls. References: [2] http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-July/000092.html
This issue affects the versions of the mediawiki package, as shipped with Fedora release of 12 and 13. Please fix.
Created mediawiki tracking bugs for this issue Affects: fedora-all [bug 620226]