CVE-2018-0505

Name
CVE-2018-0505
Description
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://phabricator.wikimedia.org/T194605
Patch https://lists.wikimedia.org/pipermail/wikitech-l/2018-September/090849.html
Third Party Advisory https://www.debian.org/security/2018/dsa-4301
Third Party Advisory http://www.securitytracker.com/id/1041695
REDHAT https://access.redhat.com/errata/RHSA-2019:3142
REDHAT https://access.redhat.com/errata/RHSA-2019:3238
REDHAT https://access.redhat.com/errata/RHSA-2019:3813

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* mediawiki >= 1.31.0 < 1.31.1
cpe:2.3:a:mediawiki:mediawiki:1.29.3:*:*:*:*:*:*:* mediawiki == None == 1.29.3
cpe:2.3:a:mediawiki:mediawiki:1.27.5:*:*:*:*:*:*:* mediawiki == None == 1.27.5
cpe:2.3:a:mediawiki:mediawiki:1.30.1:*:*:*:*:*:*:* mediawiki == None == 1.30.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status