CVE-2021-45471Incorrect Authorization in Mediawiki

Severity
5.3MEDIUMNVD
EPSS
0.3%
top 45.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24
Latest updateDec 25

Description

In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

Also affects: Fedora 35

🔴Vulnerability Details

2
GHSA
GHSA-mrv7-g7p3-qw62: In MediaWiki through 12021-12-25
OSV
CVE-2021-45471: In MediaWiki through 12021-12-24

📋Vendor Advisories

1
Red Hat
mediawiki: blocked IP addresses are allowed to edit EntitySchema items2021-12-17