CVE-2018-0503Improper Privilege Management in Mediawiki

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 40.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4
Latest updateMay 13

Description

Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

Packagistmediawiki/core1.27.01.27.5+3
debiandebian/mediawiki< mediawiki 1:1.31.1-1 (bookworm)
NVDmediawiki/mediawiki1.31.01.31.1+3
Debianmediawiki/mediawiki< 1:1.31.1-1+3
CVEListV5mediawiki/mediawikibefore 1.31.1, 1.30.1, 1.29.3 and 1.27.5

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

3
GHSA
Mediawiki Improper Privilege Management2022-05-13
OSV
Mediawiki Improper Privilege Management2022-05-13
OSV
CVE-2018-0503: Mediawiki 12018-10-04

📋Vendor Advisories

2
Red Hat
mediawiki: $wgRateLimits (rate limit / ping limiter) entry for 'user' overrides that for 'newbie'2018-09-24
Debian
CVE-2018-0503: mediawiki - Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where co...2018

💬Community

2
Bugzilla
CVE-2018-0503 mediawiki: $wgRateLimits (rate limit / ping limiter) entry for 'user' overrides that for 'newbie'2018-09-28
Bugzilla
CVE-2018-0503 mediawiki: $wgRateLimits (rate limit / ping limiter) entry for 'user' overrides that for 'newbie' [fedora-all]2018-09-28
CVE-2018-0503 — Improper Privilege Management | cvebase