Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Untriaged
(browse all)
created 2 days, 21 hours ago
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, …

The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.

Affected products

MediaWiki
  • ==1.2x before 1.21.4
  • ==1.22.x before 1.22.1
  • ==before 1.19.10

Matching in nixpkgs

Package maintainers