CVE-2022-41767
published 2022-12-26CVE-2022-41767: An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP address are…
PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.64%
47.0th percentile
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP address are reassigned to a user (using reassignEdits.php), the changes will still be attributed to the IP address on Special:Contributions when doing a range lookup.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.35.8-1 (bookworm) | mediawiki 1:1.35.8-1 (bookworm) |
| mediawiki | mediawiki | < 1.35.8 | 1.35.8 |
| mediawiki | mediawiki | >= 0 < 1:1.35.8-1~deb11u1 | 1:1.35.8-1~deb11u1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.8-1 | 1:1.35.8-1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.8-1 | 1:1.35.8-1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.8-1 | 1:1.35.8-1 |
| mediawiki | mediawiki | >= 1.36.0 < 1.37.5 | 1.37.5 |
| mediawiki | mediawiki | >= 1.38.0 < 1.38.3 | 1.38.3 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-41767: An issue was discovered in MediaWiki before 1
osv·2022-12-26·CVSS 5.3
CVE-2022-41767 [MEDIUM] CVE-2022-41767: An issue was discovered in MediaWiki before 1
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP address are reassigned to a user (using reassignEdits.php), the changes will still be attributed to the IP address on Special:Contributions when doing a range lookup.
GHSA
GHSA-4jqr-r4vf-pqw6: An issue was discovered in MediaWiki before 1
ghsa_unreviewed·2022-12-26
CVE-2022-41767 [MEDIUM] CWE-200 GHSA-4jqr-r4vf-pqw6: An issue was discovered in MediaWiki before 1
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP address are reassigned to a user (using reassignEdits.php), the changes will still be attributed to the IP address on Special:Contributions when doing a range lookup.
Red Hat
mediawiki: reassignEdits doesn't update results in an IP range check on Special:Contributions
vendor_redhat·2022-12-26·CVSS 5.3
CVE-2022-41767 [MEDIUM] mediawiki: reassignEdits doesn't update results in an IP range check on Special:Contributions
mediawiki: reassignEdits doesn't update results in an IP range check on Special:Contributions
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP address are reassigned to a user (using reassignEdits.php), the changes will still be attributed to the IP address on Special:Contributions when doing a range lookup.
Package: mediawiki (Red Hat OpenShift Container Platform 3.11) - Out of support scope
Debian
CVE-2022-41767: mediawiki - An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.3...
vendor_debian·2022·CVSS 5.3
CVE-2022-41767 [MEDIUM] CVE-2022-41767: mediawiki - An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.3...
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP address are reassigned to a user (using reassignEdits.php), the changes will still be attributed to the IP address on Special:Contributions when doing a range lookup.
Scope: local
bookworm: resolved (fixed in 1:1.35.8-1)
bullseye: resolved (fixed in 1:1.35.8-1~deb11u1)
forky: resolved (fixed in 1:1.35.8-1)
sid: resolved (fixed in 1:1.35.8-1)
trixie: resolved (fixed in 1:1.35.8-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-26
Published