CVE-2018-0504
published 2018-10-04CVE-2018-0504: Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
PriorityP431medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
2.80%
85.0th percentile
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | mediawiki | < mediawiki 1:1.31.1-1 (bookworm) | mediawiki 1:1.31.1-1 (bookworm) |
| mediawiki | core | >= 1.27.0 < 1.27.5 | 1.27.5 |
| mediawiki | core | >= 1.29.0 < 1.29.3 | 1.29.3 |
| mediawiki | core | >= 1.30.0 < 1.30.1 | 1.30.1 |
| mediawiki | core | >= 1.31.0 < 1.31.1 | 1.31.1 |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | >= 0 < 1:1.31.1-1 | 1:1.31.1-1 |
| mediawiki | mediawiki | >= 0 < 1:1.31.1-1 | 1:1.31.1-1 |
| mediawiki | mediawiki | >= 0 < 1:1.31.1-1 | 1:1.31.1-1 |
| mediawiki | mediawiki | >= 0 < 1:1.31.1-1 | 1:1.31.1-1 |
| mediawiki | mediawiki | >= 1.31.0 < 1.31.1 | 1.31.1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mediawiki: Information exposure when a log event is (partially) hidden
vendor_redhat·2018-09-24·CVSS 6.5
CVE-2018-0504 [MEDIUM] CWE-200 mediawiki: Information exposure when a log event is (partially) hidden
mediawiki: Information exposure when a log event is (partially) hidden
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
Package: mediawiki (Red Hat OpenShift Container Platform 3.11) - Fix deferred
Package: mediawiki123 (Red Hat OpenShift Container Platform 3.6) - Out of support scope
Package: mediawiki123 (Red Hat OpenShift Container Platform 3.7) - Out of support scope
Package: mediawiki (Red Hat OpenShift Container Platform 4) - Fix deferred
Debian
CVE-2018-0504: mediawiki - Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information ...
vendor_debian·2018·CVSS 6.5
CVE-2018-0504 [MEDIUM] CVE-2018-0504: mediawiki - Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information ...
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
Scope: local
bookworm: resolved (fixed in 1:1.31.1-1)
bullseye: resolved (fixed in 1:1.31.1-1)
forky: resolved (fixed in 1:1.31.1-1)
sid: resolved (fixed in 1:1.31.1-1)
trixie: resolved (fixed in 1:1.31.1-1)
OSV
Mediawiki information disclosure vulnerability
osv·2022-05-13
CVE-2018-0504 [MEDIUM] Mediawiki information disclosure vulnerability
Mediawiki information disclosure vulnerability
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
GHSA
Mediawiki information disclosure vulnerability
ghsa·2022-05-13
CVE-2018-0504 [MEDIUM] CWE-532 Mediawiki information disclosure vulnerability
Mediawiki information disclosure vulnerability
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
OSV
CVE-2018-0504: Mediawiki 1
osv·2018-10-04·CVSS 6.5
CVE-2018-0504 [MEDIUM] CVE-2018-0504: Mediawiki 1
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-0504 mediawiki: Information exposure when a log event is (partially) hidden [fedora-all]
bugzilla·2018-09-28·CVSS 6.5
CVE-2018-0504 [MEDIUM] CVE-2018-0504 mediawiki: Information exposure when a log event is (partially) hidden [fedora-all]
CVE-2018-0504 mediawiki: Information exposure when a log event is (partially) hidden [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2018-0504 mediawiki: Information exposure when a log event is (partially) hidden
bugzilla·2018-09-28·CVSS 6.5
CVE-2018-0504 [MEDIUM] CVE-2018-0504 mediawiki: Information exposure when a log event is (partially) hidden
CVE-2018-0504 mediawiki: Information exposure when a log event is (partially) hidden
As reported:
A flaw was found in mediawiki. When a log event is (partially) hidden Special:Redirect/logid can link to the incorrect log and reveal hidden information.
Upstream bug:
https://phabricator.wikimedia.org/T187638
References:
https://lists.wikimedia.org/pipermail/mediawiki-announce/2018-September/000223.html
Discussion:
Created mediawiki tracking bugs for this issue:
Affects: fedora-all [bug 1634170]
---
Updating affected products; mediawiki-123 is the container name, mediawiki123 is the package name.
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 3.10
Via RHSA-2019:3238 https://access.redhat.com/errata/RHSA-2019:3238
---
This bug
Bugzilla
CVE-2018-5950 mailman: Cross-site scripting (XSS) vulnerability in web UI
bugzilla·2018-01-24·CVSS 6.1
CVE-2018-5950 [MEDIUM] CVE-2018-5950 mailman: Cross-site scripting (XSS) vulnerability in web UI
CVE-2018-5950 mailman: Cross-site scripting (XSS) vulnerability in web UI
Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Reference:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=888201
Discussion:
Created mailman tracking bugs for this issue:
Affects: fedora-all [bug 1537942]
---
Upstream bug report:
https://bugs.launchpad.net/mailman/+bug/1747209
Upstream commit:
https://bazaar.launchpad.net/~mailman-coders/mailman/2.1/revision/1743
Upstream announcement:
https://www.mail-archive.com/[email protected]/msg70478.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:0504 https://access.redhat.
http://www.securitytracker.com/id/1041695https://access.redhat.com/errata/RHSA-2019:3238https://access.redhat.com/errata/RHSA-2019:3813https://lists.wikimedia.org/pipermail/wikitech-l/2018-September/090849.htmlhttps://phabricator.wikimedia.org/T187638https://www.debian.org/security/2018/dsa-4301http://www.securitytracker.com/id/1041695https://access.redhat.com/errata/RHSA-2019:3238https://access.redhat.com/errata/RHSA-2019:3813https://lists.wikimedia.org/pipermail/wikitech-l/2018-September/090849.htmlhttps://phabricator.wikimedia.org/T187638https://www.debian.org/security/2018/dsa-4301
2018-10-04
Published