CVE-2012-4379Improper Access Control in Mediawiki

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 37.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 19
Latest updateMay 17

Description

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct clickjacking attacks via an embedded API response in an IFRAME element.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.19.2-1 (bookworm)
Debianmediawiki/mediawiki< 1:1.19.2-1+3
NVDmediawiki/mediawiki1.18.4+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vj53-2xmv-77mc: MediaWiki before 12022-05-17
OSV
CVE-2012-4379: MediaWiki before 12017-10-19

📋Vendor Advisories

1
Debian
CVE-2012-4379: mediawiki - MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-...2012

💬Community

3
Bugzilla
CVE-2012-4379 mediawiki: CSRF tokens, available via API, not protected when X-Frame-Options headers used2012-08-31
Bugzilla
CVE-2012-4377 CVE-2012-4378 CVE-2012-4379 CVE-2012-4380 CVE-2012-4381 mediawiki various flaws [fedora-all]2012-08-31
Bugzilla
CVE-2012-4379 CVE-2012-4380 CVE-2012-4381 mediawiki various flaws [epel-5]2012-08-31
CVE-2012-4379 — Improper Access Control in Mediawiki | cvebase