CVE-2012-0046
published 2012CVE-2012-0046: mediawiki allows deleted text to be exposed Scope: local bookworm: resolved (fixed in 1:1.15.5-6) bullseye: resolved (fixed in 1:1.15.5-6) forky: resolved…
high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.37%
69.1th percentile
mediawiki allows deleted text to be exposed
Scope: local
bookworm: resolved (fixed in 1:1.15.5-6)
bullseye: resolved (fixed in 1:1.15.5-6)
forky: resolved (fixed in 1:1.15.5-6)
sid: resolved (fixed in 1:1.15.5-6)
trixie: resolved (fixed in 1:1.15.5-6)
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.15.5-6 (bookworm) | mediawiki 1:1.15.5-6 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Bugzilla
CVE-2012-0046 mediawiki: prop=revisions allows deleted text to be exposed through cache pollution
bugzilla·2012-01-12·CVSS 7.5
CVE-2012-0046 [HIGH] CVE-2012-0046 mediawiki: prop=revisions allows deleted text to be exposed through cache pollution
CVE-2012-0046 mediawiki: prop=revisions allows deleted text to be exposed through cache pollution
MediaWiki 1.17.2 and 1.18.1 were released to correct a security flaw in its API where prop=revisions would expose deleted text to unprivileged users through cache pollution.
MediaWiki 1.16 is no longer supported upstream, but this flaw does seem to affect that version, as per the code changes (r108682).
References:
https://www.mediawiki.org/wiki/Special:Code/MediaWiki/108682
https://bugzilla.wikimedia.org/show_bug.cgi?id=33117
http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_17_2/phase3/RELEASE-NOTES
Discussion:
Created mediawiki tracking bugs for this issue
Affects: fedora-all [bug 773741]
---
Created mediawiki116 tracking bugs for this issue
Affects: epel-all [bug 773742]
---
Bugzilla
CVE-2012-0046 mediawiki: prop=revisions allows deleted text to be exposed through cache pollution [epel-all]
bugzilla·2012-01-12·CVSS 7.5
CVE-2012-0046 [HIGH] CVE-2012-0046 mediawiki: prop=revisions allows deleted text to be exposed through cache pollution [epel-all]
CVE-2012-0046 mediawiki: prop=revisions allows deleted text to be exposed through cache pollution [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraprojec
2012
Published