2023-11-07 21:03:21 +00:00

112 lines
3.7 KiB
JSON

{
"id": "CVE-2023-36674",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-08-20T18:15:09.930",
"lastModified": "2023-11-07T04:16:41.150",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax."
},
{
"lang": "es",
"value": "Se descubri\u00f3 un problema en MediaWiki antes de 1.35.11, 1.36.x hasta 1.38.x antes de 1.38.7, 1.39.x antes de 1.39.4 y 1.40.x antes de 1.40.1. Es posible omitir la Lista de Im\u00e1genes Incorrectas (tambi\u00e9n conocida como badFile) utilizando el par\u00e1metro de thumb (tambi\u00e9n conocido como Manualthumb) de la Sintaxis del Archivo."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.35.11",
"matchCriteriaId": "FB8FFF65-64E2-4995-9D76-4A76E9165631"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*",
"versionStartIncluding": "1.36.0",
"versionEndExcluding": "1.38.7",
"matchCriteriaId": "604E0A5B-4554-46AA-98AF-608A2CCDBF4F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*",
"versionStartIncluding": "1.39.0",
"versionEndExcluding": "1.39.4",
"matchCriteriaId": "8B25814F-6A96-432B-9E6B-458E8FAA8B32"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.40.0:*:*:*:*:*:*:*",
"matchCriteriaId": "1610A245-C33E-4BF6-B8C3-DF7E6F13FC69"
}
]
}
]
}
],
"references": [
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2UIVGYECQGTUC2LLPVCZBPDLCTOHL2F6/",
"source": "cve@mitre.org"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CHRX6DSLAMVXCV2YMJEWOLTBEYSESE5/",
"source": "cve@mitre.org"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DOAXEGYBOEM4JWB4J3BDH73NK2LCYC3O/",
"source": "cve@mitre.org"
},
{
"url": "https://phabricator.wikimedia.org/T335612",
"source": "cve@mitre.org",
"tags": [
"Issue Tracking",
"Patch"
]
}
]
}