CVE-2017-8810 log
| Source |
|
| Severity | Low |
| Remote | Yes |
| Type | Information disclosure |
| Description | MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-490 | mediawiki | 1.29.1-1 | 1.29.2-1 | High | Fixed |
| Date | Advisory | Group | Package | Severity | Type |
|---|---|---|---|---|---|
| 15 Nov 2017 | ASA-201711-20 | AVG-490 | mediawiki | High | multiple issues |