Bug 1815173 (CVE-2020-10534) - CVE-2020-10534 mediawiki: IP range evaluation issue allows blocked users regain escalated privileges
Summary: CVE-2020-10534 mediawiki: IP range evaluation issue allows blocked users rega...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2020-10534
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1815174
Blocks: 1815175
TreeView+ depends on / blocked
 
Reported: 2020-03-19 17:19 UTC by Guilherme de Almeida Suckevicz
Modified: 2020-04-06 00:27 UTC (History)
11 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2020-04-02 10:31:57 UTC
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2020-03-19 17:19:24 UTC
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an IP address is contained in two ranges, one of which is locally disabled.

Reference:
https://phabricator.wikimedia.org/T229731

Upstream commit:
https://gerrit.wikimedia.org/r/#/q/I9cc5fb2c08c78bbd797a5fc6d89f4577c8cc118b

Comment 1 Guilherme de Almeida Suckevicz 2020-03-19 17:20:21 UTC
Created mediawiki tracking bugs for this issue:

Affects: fedora-all [bug 1815174]

Comment 2 Michael Cronenworth 2020-03-20 17:40:01 UTC
This issue is for the *extension* GlobalBlocking. It is not shipped as a bundled extension and the patch is *not* in the core of mediawiki. This bug should not have been opened.

Comment 3 Mark Cooper 2020-04-02 06:00:56 UTC
Agreed, seems strange. 

Setting OpenShift 3 and 4 to not affected. 

Whilst MediaWiki does include extensions by default GlobalBlocking is not one of them. Not even sure the status of the extension given that it's been in beta for several years: 
    - https://www.mediawiki.org/wiki/Extension:GlobalBlocking
    - https://www.mediawiki.org/wiki/Extension_talk:GlobalBlocking

Confirmed the following OpenShift images don't include GlobalBlocking. 
     - openshift3/mediawiki
     - openshift4/mediawiki

Comment 4 Product Security DevOps Team 2020-04-02 10:31:57 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-10534


Note You need to log in before you can comment on or make changes to this bug.