fkie_cve-2013-2032
Vulnerability from fkie_nvd
Published
2013-11-18 02:55
Modified
2025-04-11 00:51
Severity ?
Summary
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:ChangePassword, which allows remote attackers to bypass the intended restrictions of an extension that only implements one of these blocks.
References
secalert@redhat.comhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/105784.htmlThird Party Advisory
secalert@redhat.comhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/105825.htmlThird Party Advisory
secalert@redhat.comhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/106293.htmlThird Party Advisory
secalert@redhat.comhttp://lists.wikimedia.org/pipermail/mediawiki-announce/2013-April/000129.htmlPatch
secalert@redhat.comhttp://secunia.com/advisories/55433
secalert@redhat.comhttp://security.gentoo.org/glsa/glsa-201310-21.xmlThird Party Advisory
secalert@redhat.comhttps://bugzilla.wikimedia.org/show_bug.cgi?id=46590Issue Tracking, Patch
af854a3a-2127-422b-91ae-364da2661108http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105784.htmlThird Party Advisory
af854a3a-2127-422b-91ae-364da2661108http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105825.htmlThird Party Advisory
af854a3a-2127-422b-91ae-364da2661108http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106293.htmlThird Party Advisory
af854a3a-2127-422b-91ae-364da2661108http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-April/000129.htmlPatch
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/55433
af854a3a-2127-422b-91ae-364da2661108http://security.gentoo.org/glsa/glsa-201310-21.xmlThird Party Advisory
af854a3a-2127-422b-91ae-364da2661108https://bugzilla.wikimedia.org/show_bug.cgi?id=46590Issue Tracking, Patch
Impacted products
Vendor Product Version
mediawiki mediawiki *
mediawiki mediawiki 1.1.0
mediawiki mediawiki 1.10.0
mediawiki mediawiki 1.10.0
mediawiki mediawiki 1.10.0
mediawiki mediawiki 1.10.1
mediawiki mediawiki 1.10.2
mediawiki mediawiki 1.10.3
mediawiki mediawiki 1.10.4
mediawiki mediawiki 1.11
mediawiki mediawiki 1.11.0
mediawiki mediawiki 1.11.0
mediawiki mediawiki 1.11.1
mediawiki mediawiki 1.11.2
mediawiki mediawiki 1.12.0
mediawiki mediawiki 1.12.0
mediawiki mediawiki 1.12.1
mediawiki mediawiki 1.12.2
mediawiki mediawiki 1.12.3
mediawiki mediawiki 1.12.4
mediawiki mediawiki 1.13.0
mediawiki mediawiki 1.13.0
mediawiki mediawiki 1.13.0
mediawiki mediawiki 1.13.1
mediawiki mediawiki 1.13.2
mediawiki mediawiki 1.13.3
mediawiki mediawiki 1.13.4
mediawiki mediawiki 1.14.0
mediawiki mediawiki 1.14.0
mediawiki mediawiki 1.14.1
mediawiki mediawiki 1.15.0
mediawiki mediawiki 1.15.0
mediawiki mediawiki 1.15.1
mediawiki mediawiki 1.15.2
mediawiki mediawiki 1.15.3
mediawiki mediawiki 1.15.4
mediawiki mediawiki 1.15.5
mediawiki mediawiki 1.16.0
mediawiki mediawiki 1.16.0
mediawiki mediawiki 1.16.0
mediawiki mediawiki 1.16.0
mediawiki mediawiki 1.16.1
mediawiki mediawiki 1.16.2
mediawiki mediawiki 1.17
mediawiki mediawiki 1.17
mediawiki mediawiki 1.17.0
mediawiki mediawiki 1.17.0
mediawiki mediawiki 1.17.1
mediawiki mediawiki 1.17.2
mediawiki mediawiki 1.17.3
mediawiki mediawiki 1.17.4
mediawiki mediawiki 1.18
mediawiki mediawiki 1.18
mediawiki mediawiki 1.18.0
mediawiki mediawiki 1.18.0
mediawiki mediawiki 1.18.1
mediawiki mediawiki 1.18.2
mediawiki mediawiki 1.18.3
mediawiki mediawiki 1.19
mediawiki mediawiki 1.19
mediawiki mediawiki 1.19
mediawiki mediawiki 1.19.0
mediawiki mediawiki 1.19.1
mediawiki mediawiki 1.19.2
mediawiki mediawiki 1.19.3
mediawiki mediawiki 1.19.4
mediawiki mediawiki 1.20.1
mediawiki mediawiki 1.20.2
mediawiki mediawiki 1.20.3
mediawiki mediawiki 1.20.4
fedoraproject fedora 17
fedoraproject fedora 18
fedoraproject fedora 19
gentoo linux *



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "644124C5-D3F7-43A9-8225-805FDAC3DF7C",
              "versionEndIncluding": "1.19.5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.1.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "1C96D337-1D37-4ADE-871D-9829928EE80B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.10.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "E0983C0E-9035-4256-AC99-C2C81C1634E6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.10.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "76F47EF6-2695-44FD-B4B0-9DE911BB57CC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.10.0:rc2:*:*:*:*:*:*",
              "matchCriteriaId": "FC61592E-7479-45C1-9263-D608B644EE79",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.10.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "5460DB30-FA14-4017-BC8B-15F9451469F3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.10.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "ED2392D6-6ACF-4715-BBCD-B6DA9B91C750",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.10.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "B0071C35-877F-44C6-BC39-B1AE885D7313",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.10.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "AD83CF24-FC29-40C4-8B07-5FB6591E9812",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.11:*:*:*:*:*:*:*",
              "matchCriteriaId": "8C54ADEF-F360-41C6-AE27-B6D12E5BAF9A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.11.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "66A92668-4B5D-40A4-9A14-E7AD10086933",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.11.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "7266D827-F77D-4CC3-8237-4B35D072ACF8",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.11.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "4DB5EF0E-4E1B-4131-9142-5FBB59C235D5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.11.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "F59B5992-716F-4901-BDD1-0C7E24BF9148",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "746023B5-2472-4FC9-BEDF-FE6A321F12B9",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "0D18C85B-E82B-46AE-959E-3FD32DB6F294",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "66714539-F1E1-4C16-AA12-059EEB1B9DF6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "A80044C9-9F76-468E-84F7-D7D529004AE6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "C7CD7F5A-F4E4-45B6-9179-BD1BCD75D297",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.12.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "C7BC3705-27C7-4969-AB6A-E7C09C708C21",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "79CDE6D3-A26D-4ECD-B949-B9DDB53F67C3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "D3CC82BE-8DEA-47D7-B6B7-2FFDFB728ADE",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.0:rc2:*:*:*:*:*:*",
              "matchCriteriaId": "AFD79470-63A7-438B-A3BE-CABDAD7F848C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "A26F4C94-E3A5-456E-8E5E-36BA67DD4BD5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "C7C6D23B-B5C1-4F10-9F62-E81F639FF40F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "13FA8F3C-2B6C-42FB-A6CE-EC2D8614E43D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.13.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "973B7468-970D-475C-AAB2-D81833EAF12B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.14.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "3F4A0789-0496-4940-A484-8B6689AA8770",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.14.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "241370F6-4941-43B4-AAD5-32A93AAC3B80",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.14.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "9A236174-7262-478C-8C96-61428EBCC575",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.15.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "CAAC942E-1BA2-419C-B464-20529D825053",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.15.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "188AA942-A54E-4B48-A14E-1D4C2BB859EC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.15.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "07D3ECE8-29AC-491A-BD11-1753EF65DA0E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.15.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "4FA6109F-F5BE-4E65-AA9D-C1D0CB029521",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.15.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "0955D3BF-1120-40F6-87FB-D75B064E5C6A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.15.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "0BA61CFC-F48E-4B7D-A61C-4BD585E87BAF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.15.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "0BA7AA7B-9450-4AAD-8CBA-E483CD5A1CED",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.16.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "4416B074-0C5E-4DD3-AA4D-B54AC635F00D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.16.0:beta1:*:*:*:*:*:*",
              "matchCriteriaId": "EBA4FDC8-2F1B-4054-82BC-B79566ABE8E6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.16.0:beta2:*:*:*:*:*:*",
              "matchCriteriaId": "62B86D8D-5E7A-43F5-9B6A-944ED4B8E4E8",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.16.0:beta3:*:*:*:*:*:*",
              "matchCriteriaId": "E4780402-81D6-46E1-8ECD-3BCB97095B2B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.16.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "63FD259B-921D-46BF-BE6E-F963288D92F3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.16.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "5B163E10-BD02-481B-A78E-E4678C57CC75",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.17:*:*:*:*:*:*:*",
              "matchCriteriaId": "F9AC7B4F-6AE2-4FCC-80DA-0D068E479853",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.17:beta_1:*:*:*:*:*:*",
              "matchCriteriaId": "57F3C3BF-CA6A-4BCC-83CE-32560F0A437D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.17.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "B6D1B676-AE23-4FC5-8466-EB44B8F756CC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.17.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "1C3B8FFB-25AD-4165-8C87-DBF5977572FA",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.17.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "52E0CED2-EF96-4052-A4BC-4657163B4FE5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.17.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "2E8D954D-484E-4DAA-8E0E-6CEAC17BBA22",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.17.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "341D904D-A6D6-4644-B67B-D1D62BCFEDEA",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.17.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "7C3356EA-5FD5-478E-882B-2D7C10011537",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.18:*:*:*:*:*:*:*",
              "matchCriteriaId": "6EBD4E4C-DE1D-4007-BABF-A82ECBC2C8B1",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.18:beta_1:*:*:*:*:*:*",
              "matchCriteriaId": "EA045993-D0DE-4878-A9CF-5C671F3E5196",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.18.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "15426470-3C5F-41AC-B64B-BA021D9F5EA5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.18.0:rc1:*:*:*:*:*:*",
              "matchCriteriaId": "061DD021-3FAA-43D0-9ED2-6E60BF7E6CAF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.18.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "E8B305B8-97DE-45C7-B7A7-B1D1AB32D511",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.18.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "6BF1EE8B-18BA-49AE-BAA1-187A2F5B1D06",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.18.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "6F46B49A-D5B6-458E-8217-A5F5B045B76F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19:*:*:*:*:*:*:*",
              "matchCriteriaId": "93D7105D-3CF1-49FF-9F51-088C58F19003",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19:beta_1:*:*:*:*:*:*",
              "matchCriteriaId": "F647077F-52FD-460B-9511-85812A1447FD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19:beta_2:*:*:*:*:*:*",
              "matchCriteriaId": "BB5A8AFF-EF0E-490C-8833-FF1071563979",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "A7C29D44-2964-483F-B672-27B5CE471DA6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "172FEFE5-9900-49D0-9E14-2FA4A7912D23",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "CA3205F5-3A29-4D45-AC95-83174F8969BB",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "5547DA02-3BEC-4278-A714-25CCB820AA79",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.19.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "A3E5609D-EC04-4088-9B61-ABDD256200F7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.20.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "59319309-D926-4353-8E0C-1FE0CB97E4D5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.20.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "DA15B197-EC42-49F0-8764-E315CDA7EA03",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.20.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "ECD4CD3D-6022-4F75-A524-5A5247EF23AD",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:mediawiki:mediawiki:1.20.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "75B95AE3-6FA0-44BD-A78A-F059613B57EC",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*",
              "matchCriteriaId": "2DA9D861-3EAF-42F5-B0B6-A4CD7BDD6188",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:18:*:*:*:*:*:*:*",
              "matchCriteriaId": "E14271AE-1309-48F3-B9C6-D7DEEC488279",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*",
              "matchCriteriaId": "5991814D-CA77-4C25-90D2-DB542B17E0AD",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "647BA336-5538-4972-9271-383A0EC9378E",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:ChangePassword, which allows remote attackers to bypass the intended restrictions of an extension that only implements one of these blocks."
    },
    {
      "lang": "es",
      "value": "MediaWiki anteriores a 1.19.6, y 1.20.x anteriores a 1.20.5 no permite a las extensiones prevenir cambios en las contrase\u00f1as sin usar Special:PasswordReset y Special:ChangePassword, lo cual permite a atacantes remotos sortear restricciones de acceso en extensiones que s\u00f3lo implementan uno de estos bloques."
    }
  ],
  "id": "CVE-2013-2032",
  "lastModified": "2025-04-11T00:51:21.963",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "MEDIUM",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "NETWORK",
          "authentication": "NONE",
          "availabilityImpact": "NONE",
          "baseScore": 5.0,
          "confidentialityImpact": "NONE",
          "integrityImpact": "PARTIAL",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "version": "2.0"
        },
        "exploitabilityScore": 10.0,
        "impactScore": 2.9,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ]
  },
  "published": "2013-11-18T02:55:07.297",
  "references": [
    {
      "source": "secalert@redhat.com",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105784.html"
    },
    {
      "source": "secalert@redhat.com",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105825.html"
    },
    {
      "source": "secalert@redhat.com",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106293.html"
    },
    {
      "source": "secalert@redhat.com",
      "tags": [
        "Patch"
      ],
      "url": "http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-April/000129.html"
    },
    {
      "source": "secalert@redhat.com",
      "url": "http://secunia.com/advisories/55433"
    },
    {
      "source": "secalert@redhat.com",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "http://security.gentoo.org/glsa/glsa-201310-21.xml"
    },
    {
      "source": "secalert@redhat.com",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "url": "https://bugzilla.wikimedia.org/show_bug.cgi?id=46590"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105784.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105825.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106293.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Patch"
      ],
      "url": "http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-April/000129.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://secunia.com/advisories/55433"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory"
      ],
      "url": "http://security.gentoo.org/glsa/glsa-201310-21.xml"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "url": "https://bugzilla.wikimedia.org/show_bug.cgi?id=46590"
    }
  ],
  "sourceIdentifier": "secalert@redhat.com",
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…