CVE-2021-30157
published 2021-04-06CVE-2021-30157: An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.41%
69.6th percentile
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages are output in HTML unescaped, leading to XSS.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | mediawiki | < mediawiki 1:1.35.2-1 (bookworm) | mediawiki 1:1.35.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mediawiki | mediawiki | < 1.31.12 | 1.31.12 |
| mediawiki | mediawiki | >= 0 < 1:1.35.2-1 | 1:1.35.2-1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.2-1 | 1:1.35.2-1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.2-1 | 1:1.35.2-1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.2-1 | 1:1.35.2-1 |
| mediawiki | mediawiki | >= 1.32.0 < 1.35.2 | 1.35.2 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5586-f3jq-cmhq: An issue was discovered in MediaWiki before 1
ghsa_unreviewed·2022-05-24
CVE-2021-30157 [MEDIUM] CWE-79 GHSA-5586-f3jq-cmhq: An issue was discovered in MediaWiki before 1
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages are output in HTML unescaped, leading to XSS.
OSV
CVE-2021-30157: An issue was discovered in MediaWiki before 1
osv·2021-04-06·CVSS 6.1
CVE-2021-30157 [MEDIUM] CVE-2021-30157: An issue was discovered in MediaWiki before 1
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages are output in HTML unescaped, leading to XSS.
Red Hat
mediawiki: XSS due to unescaped messages used in HTML on ChangesList pages
vendor_redhat·2021-03-22·CVSS 6.1
CVE-2021-30157 [MEDIUM] CWE-79 mediawiki: XSS due to unescaped messages used in HTML on ChangesList pages
mediawiki: XSS due to unescaped messages used in HTML on ChangesList pages
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages are output in HTML unescaped, leading to XSS.
In mediawiki package on ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages are outputted in HTML unescaped, which could leading to Cross-site Scripting (XSS).
Statement: The mediawiki package was removed from OpenShift Container Platform (OCP) in version 4.3, therefore for OCP 4 has been marked as out of support scope.
Package: mediawiki (Red Hat OpenShift Container Platform 3.
Debian
CVE-2021-30157: mediawiki - An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x be...
vendor_debian·2021·CVSS 6.1
CVE-2021-30157 [MEDIUM] CVE-2021-30157: mediawiki - An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x be...
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages are output in HTML unescaped, leading to XSS.
Scope: local
bookworm: resolved (fixed in 1:1.35.2-1)
bullseye: resolved (fixed in 1:1.35.2-1)
forky: resolved (fixed in 1:1.35.2-1)
sid: resolved (fixed in 1:1.35.2-1)
trixie: resolved (fixed in 1:1.35.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/26UJGHF7LJDOCQN6A3Z4PM7PYRKENJHE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2OMSV7B2TCFBOCICN3B4SMQP5HVRJQIT/https://phabricator.wikimedia.org/T278058https://security.gentoo.org/glsa/202107-40https://www.debian.org/security/2021/dsa-4889https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/26UJGHF7LJDOCQN6A3Z4PM7PYRKENJHE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2OMSV7B2TCFBOCICN3B4SMQP5HVRJQIT/https://phabricator.wikimedia.org/T278058https://security.gentoo.org/glsa/202107-40https://www.debian.org/security/2021/dsa-4889
2021-04-06
Published