René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

107 lines
3.0 KiB
JSON

{
"id": "CVE-2015-2940",
"sourceIdentifier": "cve@mitre.org",
"published": "2015-04-13T14:59:13.520",
"lastModified": "2016-12-07T18:11:04.270",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of certain users for requests that retrieve sensitive user information via unspecified vectors."
},
{
"lang": "es",
"value": "Vulnerabilidad de CSRF en la extensi\u00f3n CheckUser para MediaWiki permite a atacantes remotos secuestrar la autenticaci\u00f3n de ciertos usuarios para peticiones que solicitan informaci\u00f3n sensible de usuario a trav\u00e9s de vectores no especificados."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:checkuser:-:*:*:*:*:mediawiki:*:*",
"matchCriteriaId": "AF8654AE-7741-4CD6-A1C1-1C70CF29DEED"
}
]
}
]
}
],
"references": [
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:200",
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2015/04/01/1",
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2015/04/07/3",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/73477",
"source": "cve@mitre.org"
},
{
"url": "https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-March/000175.html",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "https://phabricator.wikimedia.org/T85858",
"source": "cve@mitre.org"
},
{
"url": "https://security.gentoo.org/glsa/201510-05",
"source": "cve@mitre.org"
}
]
}