Vulnerability Description
The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address of an internal Wikimedia Foundation server by omitting X-Forwarded-For data. This resulted in an inability to properly audit and attribute various user actions performed via the FileImporter extension.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mediawiki | Mediawiki | <= 1.35.0 |
References
- https://gerrit.wikimedia.org/r/q/I24a240253c7a5c66dd493a68e8c23d95a17e1b21ExploitPatchVendor Advisory
- https://phabricator.wikimedia.org/T265810ExploitPatchVendor Advisory
- https://gerrit.wikimedia.org/r/q/I24a240253c7a5c66dd493a68e8c23d95a17e1b21ExploitPatchVendor Advisory
- https://phabricator.wikimedia.org/T265810ExploitPatchVendor Advisory
FAQ
What is CVE-2020-27621?
CVE-2020-27621 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address o...
How severe is CVE-2020-27621?
CVE-2020-27621 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27621?
Check the references section above for vendor advisories and patch information. Affected products include: Mediawiki Mediawiki.