CVE-2017-8810 log
Source |
|
Severity | Low |
Remote | Yes |
Type | Information disclosure |
Description | MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-490 | mediawiki | 1.29.1-1 | 1.29.2-1 | High | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
15 Nov 2017 | ASA-201711-20 | AVG-490 | mediawiki | High | multiple issues |