Vulnerability Description
In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an IP address is contained in two ranges, one of which is locally disabled.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mediawiki | Mediawiki | <= 1.34.0 |
Related Weaknesses (CWE)
References
- https://gerrit.wikimedia.org/r/#/q/I9cc5fb2c08c78bbd797a5fc6d89f4577c8cc118bPatchVendor Advisory
- https://phabricator.wikimedia.org/T229731Vendor Advisory
- https://gerrit.wikimedia.org/r/#/q/I9cc5fb2c08c78bbd797a5fc6d89f4577c8cc118bPatchVendor Advisory
- https://phabricator.wikimedia.org/T229731Vendor Advisory
FAQ
What is CVE-2020-10534?
CVE-2020-10534 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to th...
How severe is CVE-2020-10534?
CVE-2020-10534 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-10534?
Check the references section above for vendor advisories and patch information. Affected products include: Mediawiki Mediawiki.