CVE-2021-35197
published 2021-07-02CVE-2021-35197: In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.94%
78.0th percentile
In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented).
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mediawiki | < mediawiki 1:1.35.3-1 (bookworm) | mediawiki 1:1.35.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mediawiki | mediawiki | < 1.31.15 | 1.31.15 |
| mediawiki | mediawiki | >= 0 < 1:1.35.4-1~deb11u1 | 1:1.35.4-1~deb11u1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.3-1 | 1:1.35.3-1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.3-1 | 1:1.35.3-1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.3-1 | 1:1.35.3-1 |
| mediawiki | mediawiki | >= 1.32.0 < 1.35.3 | 1.35.3 |
| mediawiki | mediawiki | >= 1.36.0 < 1.36.1 | 1.36.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8hhg-q8jv-q9c7: In MediaWiki before 1
ghsa_unreviewed·2022-05-24
CVE-2021-35197 [HIGH] CWE-668 GHSA-8hhg-q8jv-q9c7: In MediaWiki before 1
In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented).
OSV
CVE-2021-35197: In MediaWiki before 1
osv·2021-07-02·CVSS 7.5
CVE-2021-35197 [HIGH] CVE-2021-35197: In MediaWiki before 1
In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented).
Red Hat
mediawiki: blocked users are able to purge pages impacting Integrity
vendor_redhat·2021-06-22·CVSS 7.5
CVE-2021-35197 [HIGH] CWE-306 mediawiki: blocked users are able to purge pages impacting Integrity
mediawiki: blocked users are able to purge pages impacting Integrity
In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented).
An improper authorization vulnerability was found in mediawiki. Mediawiki bots may have unintended API access even when a sitewide block has been applied. An attacker can use this vulnerability to potentially utilize a bot to access the mediawiki API and conduct actions like purge pages.
Statement: The mediawiki component was removed from OpenShift Container Platform (OCP) in version 4.3 onward. Therefore the OCP 4 componen
Debian
CVE-2021-35197: mediawiki - In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x bef...
vendor_debian·2021·CVSS 7.5
CVE-2021-35197 [HIGH] CVE-2021-35197: mediawiki - In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x bef...
In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented).
Scope: local
bookworm: resolved (fixed in 1:1.35.3-1)
bullseye: resolved (fixed in 1:1.35.4-1~deb11u1)
forky: resolved (fixed in 1:1.35.3-1)
sid: resolved (fixed in 1:1.35.3-1)
trixie: resolved (fixed in 1:1.35.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2021/10/msg00003.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CJDYJQWT43GBD6GNQ4OW7JOZ6WQ6DZTN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MDBPECBWN6LWNSWIQMVXK6PP4YFEUYHA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QNEAI2T3Y65I55ZB6UE6RMC662RZTGRX/https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce%40lists.wikimedia.org/thread/YR3X4L2CPSEJVSY543AWEO65TD6APXHP/https://phabricator.wikimedia.org/T280226https://security.gentoo.org/glsa/202107-40https://www.debian.org/security/2021/dsa-4979https://lists.debian.org/debian-lts-announce/2021/10/msg00003.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CJDYJQWT43GBD6GNQ4OW7JOZ6WQ6DZTN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MDBPECBWN6LWNSWIQMVXK6PP4YFEUYHA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QNEAI2T3Y65I55ZB6UE6RMC662RZTGRX/https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce%40lists.wikimedia.org/thread/YR3X4L2CPSEJVSY543AWEO65TD6APXHP/https://phabricator.wikimedia.org/T280226https://security.gentoo.org/glsa/202107-40https://www.debian.org/security/2021/dsa-4979
2021-07-02
Published