CVE-2012-5391
published 2014-06-02CVE-2012-5391: Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to…
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.25%
81.1th percentile
Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the session_id.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.19.3-1 (bookworm) | mediawiki 1:1.19.3-1 (bookworm) |
| mediawiki | mediawiki | <= 1.18.5 | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | >= 0 < 1:1.19.3-1 | 1:1.19.3-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.3-1 | 1:1.19.3-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.3-1 | 1:1.19.3-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.3-1 | 1:1.19.3-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2012-5391: mediawiki - Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, ...
vendor_debian·2012·CVSS 6.8
CVE-2012-5391 [MEDIUM] CVE-2012-5391: mediawiki - Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, ...
Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the session_id.
Scope: local
bookworm: resolved (fixed in 1:1.19.3-1)
bullseye: resolved (fixed in 1:1.19.3-1)
forky: resolved (fixed in 1:1.19.3-1)
sid: resolved (fixed in 1:1.19.3-1)
trixie: resolved (fixed in 1:1.19.3-1)
GHSA
GHSA-3wxc-gqjr-6mh6: Session fixation vulnerability in Special:UserLogin in MediaWiki before 1
ghsa_unreviewed·2022-05-17
CVE-2012-5391 [MEDIUM] GHSA-3wxc-gqjr-6mh6: Session fixation vulnerability in Special:UserLogin in MediaWiki before 1
Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the session_id.
OSV
CVE-2012-5391: Session fixation vulnerability in Special:UserLogin in MediaWiki before 1
osv·2014-06-02·CVSS 6.8
CVE-2012-5391 [MEDIUM] CVE-2012-5391: Session fixation vulnerability in Special:UserLogin in MediaWiki before 1
Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the session_id.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks [epel-all]
bugzilla·2012-12-07·CVSS 6.8
CVE-2012-5391 [MEDIUM] CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks [epel-all]
CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue a
Bugzilla
CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks [epel-all]
bugzilla·2012-12-07·CVSS 6.8
CVE-2012-5391 [MEDIUM] CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks [epel-all]
CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue a
Bugzilla
CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks [epel-5]
bugzilla·2012-11-30·CVSS 6.8
CVE-2012-5391 [MEDIUM] CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks [epel-5]
CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for med
Bugzilla
CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks [fedora-all]
bugzilla·2012-11-30·CVSS 6.8
CVE-2012-5391 [MEDIUM] CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks [fedora-all]
CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affe
Bugzilla
CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks
bugzilla·2012-11-30·CVSS 6.8
CVE-2012-5391 [MEDIUM] CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks
CVE-2012-5391 mediawiki: Vulnerable to session fixation attacks
A session fixation flaw was found in the way MediaWiki, a wiki engine, performed maintenance of user session ids after user login / logout. A remote attacker could provide a specially-crafted URL that, when visited by an authenticated MediaWiki user, could allow the attacker to impersonate the victim.
References:
[1] http://www.gossamer-threads.com/lists/wiki/mediawiki/316419
[2] https://bugzilla.wikimedia.org/show_bug.cgi?id=40995
Discussion:
Relevant upstream patch:
[3] https://gerrit.wikimedia.org/r/gitweb?p=mediawiki%2Fcore.git;a=commit;h=d834a4892af5ea57b3ee387dad79ad1a2205acad
---
This issue affects the versions of the mediawiki package, as shipped with Fedora release of 16 and 17.
--
This issue affects the versi
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098975.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-March/100843.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-March/100845.htmlhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2012-November/000122.htmlhttps://bugzilla.wikimedia.org/show_bug.cgi?id=40995https://exchange.xforce.ibmcloud.com/vulnerabilities/83008http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098975.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-March/100843.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-March/100845.htmlhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2012-November/000122.htmlhttps://bugzilla.wikimedia.org/show_bug.cgi?id=40995https://exchange.xforce.ibmcloud.com/vulnerabilities/83008
2014-06-02
Published