CVE-2021-44858
published 2021-12-20CVE-2021-44858: An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.33%
68.0th percentile
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.35.5-1 (bookworm) | mediawiki 1:1.35.5-1 (bookworm) |
| mediawiki | mediawiki | < 1.35.5 | 1.35.5 |
| mediawiki | mediawiki | >= 0 < 1:1.35.4-1+deb11u2 | 1:1.35.4-1+deb11u2 |
| mediawiki | mediawiki | >= 0 < 1:1.35.5-1 | 1:1.35.5-1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.5-1 | 1:1.35.5-1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.5-1 | 1:1.35.5-1 |
| mediawiki | mediawiki | >= 1.36.0 < 1.36.3 | 1.36.3 |
| mediawiki | mediawiki | >= 1.37.0 < 1.37.1 | 1.37.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mediawiki: information disclosure
vendor_redhat·2021-12-16·CVSS 7.5
CVE-2021-44858 [HIGH] CWE-276 mediawiki: information disclosure
mediawiki: information disclosure
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.
A flaw was found in mediawiki. The "undo" feature (action=edit&undo=##&undoafter=###) allowed an attacker to view the contents of arbitrary revisions, regardless of whether they had permissions to do so. This was also found in the "mcrundo" and "mcrrestore" actions (action=mcrundo and action=mcrrestore).
Statement: The mediawiki package was removed from OpenShift Container Platform (OCP) in version 4.3, therefore for OCP 4 has been marked as out of support scope.
Package: medi
Debian
CVE-2021-44858: mediawiki - An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1....
vendor_debian·2021·CVSS 7.5
CVE-2021-44858 [HIGH] CVE-2021-44858: mediawiki - An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1....
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.
Scope: local
bookworm: resolved (fixed in 1:1.35.5-1)
bullseye: resolved (fixed in 1:1.35.4-1+deb11u2)
forky: resolved (fixed in 1:1.35.5-1)
sid: resolved (fixed in 1:1.35.5-1)
trixie: resolved (fixed in 1:1.35.5-1)
GHSA
GHSA-7h7h-4rmp-2qm5: An issue was discovered in MediaWiki before 1
ghsa_unreviewed·2021-12-21
CVE-2021-44858 [HIGH] CWE-276 GHSA-7h7h-4rmp-2qm5: An issue was discovered in MediaWiki before 1
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.
OSV
CVE-2021-44858: An issue was discovered in MediaWiki before 1
osv·2021-12-20·CVSS 7.5
CVE-2021-44858 [HIGH] CVE-2021-44858: An issue was discovered in MediaWiki before 1
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-20
Published