CVE-2021-30458 - log back

CVE-2021-30458 edited at 09 Apr 2021 09:53:36
Description
- An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Parsoid comment fostering allowed for inserting mostly arbitrary <meta> tags.
+ An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a <meta> tag, bypassing sanitization steps, and potentially allowing for cross-site scripting (XSS).
References
https://phabricator.wikimedia.org/T279451
+ https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/services/parsoid/+/15169a678f9f468ff6465035a32f28e8ec82003f%5E%21/
CVE-2021-30458 edited at 08 Apr 2021 19:57:18
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Cross-site scripting
Description
+ An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Parsoid comment fostering allowed for inserting mostly arbitrary <meta> tags.
References
+ https://phabricator.wikimedia.org/T279451
CVE-2021-30458 created at 08 Apr 2021 19:41:44
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes