CVE-2021-30152 - log back

CVE-2021-30152 edited at 09 Apr 2021 09:47:53
Description
- An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users could apply protections without having the right to do so via action=protect.
+ An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently have permissions for.
References
https://phabricator.wikimedia.org/T270713
+ https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/core/+/27ba9e0ef0c7ec76331fd92bc549bb2c0d60979a%5E%21/
CVE-2021-30152 edited at 08 Apr 2021 19:51:13
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Access restriction bypass
Description
+ An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users could apply protections without having the right to do so via action=protect.
References
+ https://phabricator.wikimedia.org/T270713
CVE-2021-30152 created at 08 Apr 2021 19:41:44
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes