CVE-2024-34502
published 2024-05-05CVE-2024-34502: An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will…
PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.41%
33.1th percentile
An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| mediawiki | mediawiki | < 1.39.6 | 1.39.6 |
| mediawiki | mediawiki | >= 1.40.0 < 1.40.2 | 1.40.2 |
| mediawiki | mediawiki | >= 1.41.0 < 1.41.1 | 1.41.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rq44-cfp6-2c3c: An issue was discovered in WikibaseLexeme in MediaWiki before 1
ghsa_unreviewed·2024-05-05
CVE-2024-34502 [CRITICAL] CWE-352 GHSA-rq44-cfp6-2c3c: An issue was discovered in WikibaseLexeme in MediaWiki before 1
An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.
Red Hat
mediawiki: MergeLexemes makes edits on GET requests without edit tokens
vendor_redhat·2024-05-05·CVSS 9.8
CVE-2024-34502 [CRITICAL] mediawiki: MergeLexemes makes edits on GET requests without edit tokens
mediawiki: MergeLexemes makes edits on GET requests without edit tokens
An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.
Package: mediawiki (Red Hat OpenShift Container Platform 3.11) - Out of support scope
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/WikibaseLexeme/+/1013359https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FU2FGUXXK6TMV6R52VRECLC6XCSQQISY/https://phabricator.wikimedia.org/T357101https://gerrit.wikimedia.org/r/c/mediawiki/extensions/WikibaseLexeme/+/1013359https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FU2FGUXXK6TMV6R52VRECLC6XCSQQISY/https://lists.fedoraproject.org/archives/list/[email protected]/message/FU2FGUXXK6TMV6R52VRECLC6XCSQQISY/https://phabricator.wikimedia.org/T357101
2024-05-05
Published