Vulnerability Description
Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mediawiki | Mediawiki | <= 1.23.15 |
| Debian | Debian Linux | 7.0 |
Related Weaknesses (CWE)
References
- https://bugs.debian.org/861585Third Party Advisory
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.htmlPatchRelease NotesVendor Advisory
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000209.htmlPatchRelease NotesVendor Advisory
- https://phabricator.wikimedia.org/T158689ExploitThird Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2017-0372Issue TrackingThird Party Advisory
- https://bugs.debian.org/861585Third Party Advisory
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000207.htmlPatchRelease NotesVendor Advisory
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2017-April/000209.htmlPatchRelease NotesVendor Advisory
- https://phabricator.wikimedia.org/T158689ExploitThird Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2017-0372Issue TrackingThird Party Advisory
FAQ
What is CVE-2017-0372?
CVE-2017-0372 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
How severe is CVE-2017-0372?
CVE-2017-0372 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-0372?
Check the references section above for vendor advisories and patch information. Affected products include: Mediawiki Mediawiki, Debian Debian Linux.