Vulnerability Description
Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mediawiki | Mediawiki | < 1.27.6 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://lists.wikimedia.org/pipermail/wikitech-l/2019-June/092152.htmlMailing ListRelease NotesVendor Advisory
- https://phabricator.wikimedia.org/T222038Third Party Advisory
- https://seclists.org/bugtraq/2019/Jun/12Issue TrackingMailing ListThird Party Advisory
- https://www.debian.org/security/2019/dsa-4460Third Party Advisory
- https://lists.wikimedia.org/pipermail/wikitech-l/2019-June/092152.htmlMailing ListRelease NotesVendor Advisory
- https://phabricator.wikimedia.org/T222038Third Party Advisory
- https://seclists.org/bugtraq/2019/Jun/12Issue TrackingMailing ListThird Party Advisory
- https://www.debian.org/security/2019/dsa-4460Third Party Advisory
FAQ
What is CVE-2019-12470?
CVE-2019-12470 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
How severe is CVE-2019-12470?
CVE-2019-12470 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12470?
Check the references section above for vendor advisories and patch information. Affected products include: Mediawiki Mediawiki, Debian Debian Linux.