Vulnerability Description
The Special:Contributions page in MediaWiki before 1.22.0 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mediawiki | Mediawiki | <= 1.22.0 |
Related Weaknesses (CWE)
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165193.htm
- http://www.openwall.com/lists/oss-security/2015/08/12/6
- http://www.openwall.com/lists/oss-security/2015/08/27/6
- https://github.com/wikimedia/mediawiki/commit/dc2966bd05b69321300c63fd0bd78e7c78
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-August/000179.htmlVendor Advisory
- https://phabricator.wikimedia.org/T48457
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165193.htm
- http://www.openwall.com/lists/oss-security/2015/08/12/6
- http://www.openwall.com/lists/oss-security/2015/08/27/6
- https://github.com/wikimedia/mediawiki/commit/dc2966bd05b69321300c63fd0bd78e7c78
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-August/000179.htmlVendor Advisory
- https://phabricator.wikimedia.org/T48457
FAQ
What is CVE-2013-7444?
CVE-2013-7444 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Special:Contributions page in MediaWiki before 1.22.0 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.
How severe is CVE-2013-7444?
CVE-2013-7444 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-7444?
Check the references section above for vendor advisories and patch information. Affected products include: Mediawiki Mediawiki.