CVE-2010-2787Sensitive Information Exposure in Mediawiki

Severity
4.3MEDIUMNVD
EPSS
0.6%
top 31.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 27
Latest updateMay 17

Description

api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.15.5-1 (bookworm)
Debianmediawiki/mediawiki< 1:1.15.5-1+3
NVDmediawiki/mediawiki1.15.4+75

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4c6h-6j8p-jf37: api2022-05-17
OSV
CVE-2010-2787: api2011-04-27

📋Vendor Advisories

1
Debian
CVE-2010-2787: mediawiki - api.php in MediaWiki before 1.15.5 does not prevent use of public caching header...2010

💬Community

2
Bugzilla
CVE-2010-2787 CVE-2010-2788 mediawiki various flaws [fedora-all]2010-08-01
Bugzilla
CVE-2010-2787 MediaWiki (< v1.15.5, v1.16.0): Private data leakage via public caching headers2010-08-01
CVE-2010-2787 — Sensitive Information Exposure | cvebase