CVE-2013-1817
published 2019-11-20CVE-2013-1817: MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.51%
83.0th percentile
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mediawiki | < mediawiki 1:1.19.4-1 (bookworm) | mediawiki 1:1.19.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| mediawiki | mediawiki | < 1.19.4 | 1.19.4 |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | >= 0 < 1:1.19.4-1 | 1:1.19.4-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.4-1 | 1:1.19.4-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.4-1 | 1:1.19.4-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.4-1 | 1:1.19.4-1 |
| mediawiki | mediawiki | >= 1.20.0 < 1.20.3 | 1.20.3 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jx28-fr4j-chqw: MediaWiki before 1
ghsa_unreviewed·2022-05-05
CVE-2013-1817 [MEDIUM] GHSA-jx28-fr4j-chqw: MediaWiki before 1
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
OSV
CVE-2013-1817: MediaWiki before 1
osv·2019-11-20·CVSS 7.5
CVE-2013-1817 [HIGH] CVE-2013-1817: MediaWiki before 1
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
Debian
CVE-2013-1817: mediawiki - MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.ph...
vendor_debian·2013·CVSS 7.5
CVE-2013-1817 [HIGH] CVE-2013-1817: mediawiki - MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.ph...
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
Scope: local
bookworm: resolved (fixed in 1:1.19.4-1)
bullseye: resolved (fixed in 1:1.19.4-1)
forky: resolved (fixed in 1:1.19.4-1)
sid: resolved (fixed in 1:1.19.4-1)
trixie: resolved (fixed in 1:1.19.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1816 CVE-2013-1817 mediawiki119 various flaws [epel-6]
bugzilla·2013-03-05·CVSS 7.5
CVE-2013-1816 [HIGH] CVE-2013-1816 CVE-2013-1817 mediawiki119 various flaws [epel-6]
CVE-2013-1816 CVE-2013-1817 mediawiki119 various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for mediawiki119
Bugzilla
CVE-2013-1817 MediaWiki: API action=unblock should return the user name, not the full user object
bugzilla·2013-03-05·CVSS 7.5
CVE-2013-1817 [HIGH] CVE-2013-1817 MediaWiki: API action=unblock should return the user name, not the full user object
CVE-2013-1817 MediaWiki: API action=unblock should return the user name, not the full user object
MediaWiki reports:
(bug 43518) API action=unblock should return the user name, not the full user
object
https://bugzilla.wikimedia.org/show_bug.cgi?id=43518
Discussion:
Created mediawiki119 tracking bugs for this issue
Affects: epel-6 [bug 917919]
---
Created mediawiki119 tracking bugs for this issue
Affects: fedora-18 [bug 917920]
---
mediawiki119-1.19.4-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2013-1816 CVE-2013-1817 mediawiki119 various flaws [fedora-18]
bugzilla·2013-03-05·CVSS 7.5
CVE-2013-1816 [HIGH] CVE-2013-1816 CVE-2013-1817 mediawiki119 various flaws [fedora-18]
CVE-2013-1816 CVE-2013-1817 mediawiki119 various flaws [fedora-18]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-18 tracking bug for mediawiki11
http://security.gentoo.org/glsa/glsa-201310-21.xmlhttp://www.openwall.com/lists/oss-security/2013/03/05/4http://www.securityfocus.com/bid/58305https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-1817https://exchange.xforce.ibmcloud.com/vulnerabilities/88359https://security-tracker.debian.org/tracker/CVE-2013-1817http://security.gentoo.org/glsa/glsa-201310-21.xmlhttp://www.openwall.com/lists/oss-security/2013/03/05/4http://www.securityfocus.com/bid/58305https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-1817https://exchange.xforce.ibmcloud.com/vulnerabilities/88359https://security-tracker.debian.org/tracker/CVE-2013-1817
2019-11-20
Published