CVE-2021-30158
published 2021-04-06CVE-2021-30158: An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.73%
75.2th percentile
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been compromised, and yet is not able to block any potential future use of the token by an unauthorized party.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mediawiki | < mediawiki 1:1.35.2-1 (bookworm) | mediawiki 1:1.35.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mediawiki | mediawiki | < 1.31.12 | 1.31.12 |
| mediawiki | mediawiki | >= 0 < 1:1.35.2-1 | 1:1.35.2-1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.2-1 | 1:1.35.2-1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.2-1 | 1:1.35.2-1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.2-1 | 1:1.35.2-1 |
| mediawiki | mediawiki | >= 1.32.0 < 1.35.2 | 1.35.2 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c7v8-6m32-34m3: An issue was discovered in MediaWiki before 1
ghsa_unreviewed·2022-05-24
CVE-2021-30158 [MEDIUM] CWE-287 GHSA-c7v8-6m32-34m3: An issue was discovered in MediaWiki before 1
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been compromised, and yet is not able to block any potential future use of the token by an unauthorized party.
OSV
CVE-2021-30158: An issue was discovered in MediaWiki before 1
osv·2021-04-06·CVSS 5.3
CVE-2021-30158 [MEDIUM] CVE-2021-30158: An issue was discovered in MediaWiki before 1
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been compromised, and yet is not able to block any potential future use of the token by an unauthorized party.
Red Hat
mediawiki: blocked users are unable to use Special:ResetTokens
vendor_redhat·2021-03-19·CVSS 5.3
CVE-2021-30158 [MEDIUM] CWE-287 mediawiki: blocked users are unable to use Special:ResetTokens
mediawiki: blocked users are unable to use Special:ResetTokens
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been compromised, and yet is not able to block any potential future use of the token by an unauthorized party.
In mediawiki a blocked users are not able to use Special:ResetTokens. If such user shared a token (accidentally or not) then it wasn't possible to block any potential future use of the compromised token.
Statement: The mediawiki package was removed from OpenShift Container Platform (OCP) in version 4.3, therefore for OCP 4 has been marked as out of supp
Debian
CVE-2021-30158: mediawiki - An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x be...
vendor_debian·2021·CVSS 5.3
CVE-2021-30158 [MEDIUM] CVE-2021-30158: mediawiki - An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x be...
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been compromised, and yet is not able to block any potential future use of the token by an unauthorized party.
Scope: local
bookworm: resolved (fixed in 1:1.35.2-1)
bullseye: resolved (fixed in 1:1.35.2-1)
forky: resolved (fixed in 1:1.35.2-1)
sid: resolved (fixed in 1:1.35.2-1)
trixie: resolved (fixed in 1:1.35.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2021/05/msg00003.htmlhttps://lists.debian.org/debian-lts-announce/2021/05/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/26UJGHF7LJDOCQN6A3Z4PM7PYRKENJHE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2OMSV7B2TCFBOCICN3B4SMQP5HVRJQIT/https://phabricator.wikimedia.org/T277009https://security.gentoo.org/glsa/202107-40https://www.debian.org/security/2021/dsa-4889https://lists.debian.org/debian-lts-announce/2021/05/msg00003.htmlhttps://lists.debian.org/debian-lts-announce/2021/05/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/26UJGHF7LJDOCQN6A3Z4PM7PYRKENJHE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2OMSV7B2TCFBOCICN3B4SMQP5HVRJQIT/https://phabricator.wikimedia.org/T277009https://security.gentoo.org/glsa/202107-40https://www.debian.org/security/2021/dsa-4889
2021-04-06
Published