CVE-2010-1189
published 2010-03-31CVE-2010-1189: MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses…
PriorityP422medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.76%
75.7th percentile
MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."
Affected
78 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.15.2-1 (bookworm) | mediawiki 1:1.15.2-1 (bookworm) |
| mediawiki | mediawiki | <= 1.15.1 | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cqgp-cp8g-949g: MediaWiki before 1
ghsa_unreviewed·2022-05-02
CVE-2010-1189 [MEDIUM] CWE-20 GHSA-cqgp-cp8g-949g: MediaWiki before 1
MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."
OSV
CVE-2010-1189: MediaWiki before 1
osv·2010-03-31·CVSS 5.0
CVE-2010-1189 [MEDIUM] CVE-2010-1189: MediaWiki before 1
MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."
Red Hat
MediaWiki: Two security fixes in v1.15.2
vendor_redhat·2010-03-08·CVSS 5.0
CVE-2010-1189 [MEDIUM] MediaWiki: Two security fixes in v1.15.2
MediaWiki: Two security fixes in v1.15.2
MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."
Debian
CVE-2010-1189: mediawiki - MediaWiki before 1.15.2 does not prevent wiki editors from linking to images fro...
vendor_debian·2010·CVSS 5.0
CVE-2010-1189 [MEDIUM] CVE-2010-1189: mediawiki - MediaWiki before 1.15.2 does not prevent wiki editors from linking to images fro...
MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."
Scope: local
bookworm: resolved (fixed in 1:1.15.2-1)
bullseye: resolved (fixed in 1:1.15.2-1)
forky: resolved (fixed in 1:1.15.2-1)
sid: resolved (fixed in 1:1.15.2-1)
trixie: resolved (fixed in 1:1.15.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-1150 MediaWiki v.1.15.3: Login CSRF
bugzilla·2010-04-08·CVSS 6.0
CVE-2010-1150 [MEDIUM] CVE-2010-1150 MediaWiki v.1.15.3: Login CSRF
CVE-2010-1150 MediaWiki v.1.15.3: Login CSRF
MediaWiki upstream has released:
[1] http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-April/000090.html
latest, v.1.15.3 version, addressing one cross-site request forgery
(CSRF) issue (from [1]):
"MediaWiki was found to be vulnerable to login CSRF. An attacker who
controls a user account on the target wiki can force the victim to log
in as the attacker, via a script on an external website. If the wiki is
configured to allow user scripts, say with "$wgAllowUserJs = true" in
LocalSettings.php, then the attacker can proceed to mount a
phishing-style attack against the victim to obtain their password."
Upstream bug report:
[2] https://bugzilla.wikimedia.org/show_bug.cgi?id=23076
CVE Request (and reply):
[3] http://www.openwall.com/
Bugzilla
CVE-2010-1189 CVE-2010-1190 MediaWiki: Two security fixes in v1.15.2
bugzilla·2010-03-09·CVSS 5.0
CVE-2010-1189 [MEDIUM] CVE-2010-1189 CVE-2010-1190 MediaWiki: Two security fixes in v1.15.2
CVE-2010-1189 CVE-2010-1190 MediaWiki: Two security fixes in v1.15.2
MediaWiki upstream has released new v1.15.2 version:
http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-March/000088.html
of MediaWiki fixing two security issues (from upstream announcement):
a, "A CSS validation issue was discovered which allows editors to display
external images in wiki pages. This is a privacy concern on public
wikis, since a malicious user may link to an image on a server they
control, which would allow that attacker to gather IP addresses and
other information from users of the public wiki. All sites running
publicly-editable MediaWiki installations are advised to upgrade. All
versions of MediaWiki (prior to this one) are affected."
CVE identifier of CVE-2010-1189 has been assigned to t
Bugzilla
CVE-2009-1189 dbus: invalid fix for CVE-2008-3834
bugzilla·2009-04-20·CVSS 2.1
CVE-2009-1189 [LOW] CVE-2009-1189 dbus: invalid fix for CVE-2008-3834
CVE-2009-1189 dbus: invalid fix for CVE-2008-3834
It was found that the patch to fix CVE-2008-3834 in dbus was incorrect and as a
result the flaw was never properly fixed (remote denial of service
vulnerability). This issue has been assigned CVE-2009-1189.
The upstream bug report is here:
https://bugs.freedesktop.org/show_bug.cgi?id=17803
Our bug report for CVE-2008-3834 is bug #464674 .
Discussion:
The upstream fix is here:
https://bugs.freedesktop.org/attachment.cgi?id=24436
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0018 https://rhn.redhat.com/errata/RHSA-2010-0018.html
http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.htmlhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2010-March/000088.htmlhttp://secunia.com/advisories/39022http://secunia.com/advisories/39656http://www.debian.org/security/2010/dsa-2022http://www.vupen.com/english/advisories/2010/0685http://www.vupen.com/english/advisories/2010/1001http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.htmlhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2010-March/000088.htmlhttp://secunia.com/advisories/39022http://secunia.com/advisories/39656http://www.debian.org/security/2010/dsa-2022http://www.vupen.com/english/advisories/2010/0685http://www.vupen.com/english/advisories/2010/1001
2010-03-31
Published