MediaWiki における誤った領域へのリソースの漏えいに関する脆弱性
| Title |
MediaWiki における誤った領域へのリソースの漏えいに関する脆弱性
|
| Summary |
MediaWiki には、誤った領域へのリソースの漏えいに関する脆弱性が存在します。
|
| Possible impacts |
情報を取得される、および情報を改ざんされる可能性があります。 |
| Solution |
ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date |
April 17, 2021, midnight |
| Registration Date |
Dec. 17, 2021, 12:05 p.m. |
| Last Update |
Dec. 17, 2021, 12:05 p.m. |
|
CVSS3.0 : 警告
|
| Score |
5.4
|
| Vector |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
|
CVSS2.0 : 警告
|
| Score |
5.5
|
| Vector |
AV:N/AC:L/Au:S/C:P/I:P/A:N |
Affected System
| MediaWiki |
|
MediaWiki 1.35.2 まで
|
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
| No |
Changed Details |
Date of change |
| 1 |
[2021年12月17日] 掲載 |
Dec. 17, 2021, 12:05 p.m. |
NVD Vulnerability Information
CVE-2021-31552
| Summary |
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules related to blocking accounts after account creation. Such rules would allow for user accounts to be created while blocking only the IP address used to create an account (and not the user account itself). Such rules could also be used by a nefarious, unprivileged user to catalog and enumerate any number of IP addresses related to these account creations.
|
| Publication Date |
April 22, 2021, 12:15 p.m. |
| Registration Date |
April 22, 2021, 4:01 p.m. |
| Last Update |
Nov. 21, 2024, 3:05 p.m. |
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* |
|
1.35.2 |
|
|
Related information, measures and tools
Common Vulnerabilities List