René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

156 lines
5.5 KiB
JSON

{
"id": "CVE-2008-5687",
"sourceIdentifier": "cve@mitre.org",
"published": "2008-12-19T17:30:03.360",
"lastModified": "2017-08-08T01:33:28.077",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remote attackers to obtain sensitive information via requests for files in images/deleted/."
},
{
"lang": "es",
"value": "MediaWiki versi\u00f3n 1.11, y otras versiones anteriores a 1.13.3, no protege apropiadamente contra la descarga de copias de seguridad de im\u00e1genes eliminadas, lo que podr\u00eda permitir a atacantes remotos obtener informaci\u00f3n confidencial por medio de peticiones de archivos en images/deleted/."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.11:*:*:*:*:*:*:*",
"matchCriteriaId": "8C54ADEF-F360-41C6-AE27-B6D12E5BAF9A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.11:rc1:*:*:*:*:*:*",
"matchCriteriaId": "77FBC313-0615-42D9-8617-4DE42CAA48BE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.11.1:*:*:*:*:*:*:*",
"matchCriteriaId": "4DB5EF0E-4E1B-4131-9142-5FBB59C235D5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.11.2:*:*:*:*:*:*:*",
"matchCriteriaId": "F59B5992-716F-4901-BDD1-0C7E24BF9148"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.0:*:*:*:*:*:*:*",
"matchCriteriaId": "746023B5-2472-4FC9-BEDF-FE6A321F12B9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "0D18C85B-E82B-46AE-959E-3FD32DB6F294"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.1:*:*:*:*:*:*:*",
"matchCriteriaId": "66714539-F1E1-4C16-AA12-059EEB1B9DF6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.2:*:*:*:*:*:*:*",
"matchCriteriaId": "A80044C9-9F76-468E-84F7-D7D529004AE6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.3:*:*:*:*:*:*:*",
"matchCriteriaId": "C7CD7F5A-F4E4-45B6-9179-BD1BCD75D297"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.0:*:*:*:*:*:*:*",
"matchCriteriaId": "79CDE6D3-A26D-4ECD-B949-B9DDB53F67C3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "D3CC82BE-8DEA-47D7-B6B7-2FFDFB728ADE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "AFD79470-63A7-438B-A3BE-CABDAD7F848C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.1:*:*:*:*:*:*:*",
"matchCriteriaId": "A26F4C94-E3A5-456E-8E5E-36BA67DD4BD5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.2:*:*:*:*:*:*:*",
"matchCriteriaId": "C7C6D23B-B5C1-4F10-9F62-E81F639FF40F"
}
]
}
]
}
],
"references": [
{
"url": "http://lists.wikimedia.org/pipermail/mediawiki-announce/2008-December/000080.html",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47678",
"source": "cve@mitre.org"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01256.html",
"source": "cve@mitre.org"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-December/msg01309.html",
"source": "cve@mitre.org"
}
]
}