CVE-2013-2114
published 2013-11-18CVE-2013-2114: Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 through 1.19.6 and 1.20.x before 1.20.6 allows remote attackers to execute…
PriorityP345medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.34%
81.7th percentile
Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 through 1.19.6 and 1.20.x before 1.20.6 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.19.7+dfsg-1 (bookworm) | mediawiki 1:1.19.7+dfsg-1 (bookworm) |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | >= 0 < 1:1.19.7+dfsg-1 | 1:1.19.7+dfsg-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.7+dfsg-1 | 1:1.19.7+dfsg-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.7+dfsg-1 | 1:1.19.7+dfsg-1 |
| mediawiki | mediawiki | >= 0 < 1:1.19.7+dfsg-1 | 1:1.19.7+dfsg-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-2114: mediawiki - Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19...
vendor_debian·2013·CVSS 6.8
CVE-2013-2114 [MEDIUM] CVE-2013-2114: mediawiki - Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19...
Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 through 1.19.6 and 1.20.x before 1.20.6 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
Scope: local
bookworm: resolved (fixed in 1:1.19.7+dfsg-1)
bullseye: resolved (fixed in 1:1.19.7+dfsg-1)
forky: resolved (fixed in 1:1.19.7+dfsg-1)
sid: resolved (fixed in 1:1.19.7+dfsg-1)
trixie: resolved (fixed in 1:1.19.7+dfsg-1)
GHSA
GHSA-3mhg-j5fx-98c7: Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1
ghsa_unreviewed·2022-05-17
CVE-2013-2114 [MEDIUM] GHSA-3mhg-j5fx-98c7: Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1
Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 through 1.19.6 and 1.20.x before 1.20.6 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
OSV
CVE-2013-2114: Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1
osv·2013-11-18·CVSS 6.8
CVE-2013-2114 [MEDIUM] CVE-2013-2114: Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1
Unrestricted file upload vulnerability in the chunk upload API in MediaWiki 1.19 through 1.19.6 and 1.20.x before 1.20.6 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7 [epel-6]
bugzilla·2013-05-24·CVSS 6.8
CVE-2013-2114 [MEDIUM] CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7 [epel-6]
CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7 [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for mediaw
Bugzilla
CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7 [epel-5]
bugzilla·2013-05-24·CVSS 6.8
CVE-2013-2114 [MEDIUM] CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7 [epel-5]
CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7 [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for mediaw
Bugzilla
CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7 [epel-all]
bugzilla·2013-05-24·CVSS 6.8
CVE-2013-2114 [MEDIUM] CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7 [epel-all]
CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7 [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affe
Bugzilla
CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7
bugzilla·2013-05-24·CVSS 6.8
CVE-2013-2114 [MEDIUM] CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7
CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7
One flaw was corrected in the recently-released MediaWiki 1.20.6 and 1.19.7 releases:
* MediaWiki user Marco discovered that security checks for file uploads were not being run when the file was uploaded in chunks through the API. This option has been available to users who can upload files since MediaWiki 1.19. [1]
[1] https://bugzilla.wikimedia.org/show_bug.cgi?id=48306
Discussion:
Created mediawiki tracking bugs for this issue
Affects: fedora-all [bug 967063]
Affects: epel-5 [bug 967064]
---
Created mediawiki119 tracking bugs for this issue
Affects: epel-6 [bug 967066]
---
Created mediawiki116 tracking bugs for this issue
Affects: epel-all [bug 967065]
---
mediawiki119-1.19.7-1.el6 has been pushed to the Fedora E
Bugzilla
CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7 [fedora-all]
bugzilla·2013-05-24·CVSS 6.8
CVE-2013-2114 [MEDIUM] CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7 [fedora-all]
CVE-2013-2114 mediawiki: security releases 1.20.6 and 1.19.7 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-May/000131.htmlhttp://secunia.com/advisories/55433http://security.gentoo.org/glsa/glsa-201310-21.xmlhttp://www.openwall.com/lists/oss-security/2013/05/24/3https://bugzilla.wikimedia.org/show_bug.cgi?id=48306http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-May/000131.htmlhttp://secunia.com/advisories/55433http://security.gentoo.org/glsa/glsa-201310-21.xmlhttp://www.openwall.com/lists/oss-security/2013/05/24/3https://bugzilla.wikimedia.org/show_bug.cgi?id=48306
2013-11-18
Published