CVE-2023-29141HTTP Request Smuggling in Mediawiki

Severity
9.8CRITICALNVD
EPSS
0.3%
top 47.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31

Description

An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

Packagistmediawiki/core1.39.01.39.3+2
debiandebian/mediawiki< mediawiki 1:1.39.4-1~deb12u1 (bookworm)
NVDmediawiki/mediawiki1.36.01.38.6+2
Debianmediawiki/mediawiki< 1:1.35.11-1~deb11u1+3

Also affects: Fedora 37

🔴Vulnerability Details

3
GHSA
X-Forwarded-For header allows brute-forcing autoblocked IP addresses2023-03-31
OSV
X-Forwarded-For header allows brute-forcing autoblocked IP addresses2023-03-31
OSV
CVE-2023-29141: An issue was discovered in MediaWiki before 12023-03-31

📋Vendor Advisories

2
Red Hat
mediawiki: Auto-block can occur for an untrusted X-Forwarded-For header2023-03-31
Debian
CVE-2023-29141: mediawiki - An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x befor...2023
CVE-2023-29141 — HTTP Request Smuggling in Mediawiki | cvebase