CVE-2012-4380Improper Access Control in Mediawiki

Severity
7.5HIGHNVD
EPSS
0.6%
top 31.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 19
Latest updateMay 17

Description

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an account via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.19.2-1 (bookworm)
Debianmediawiki/mediawiki< 1:1.19.2-1+3
NVDmediawiki/mediawiki1.18.4+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4fr9-73w7-j6w3: MediaWiki before 12022-05-17
OSV
CVE-2012-4380: MediaWiki before 12017-10-19

📋Vendor Advisories

1
Debian
CVE-2012-4380: mediawiki - MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to byp...2012

💬Community

3
Bugzilla
CVE-2012-4377 CVE-2012-4378 CVE-2012-4379 CVE-2012-4380 CVE-2012-4381 mediawiki various flaws [fedora-all]2012-08-31
Bugzilla
CVE-2012-4380 mediawiki: Did not prevent account creation for IP addresses blocked with GlobalBlocking2012-08-31
Bugzilla
CVE-2012-4379 CVE-2012-4380 CVE-2012-4381 mediawiki various flaws [epel-5]2012-08-31
CVE-2012-4380 — Improper Access Control in Mediawiki | cvebase