CVE-2020-11979
- EPSS 0.61%
- Veröffentlicht 01.10.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 04:59:02
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without ...
CVE-2020-26154
- EPSS 1.58%
- Veröffentlicht 30.09.2020 18:15:27
- Zuletzt bearbeitet 21.11.2024 05:19:23
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
CVE-2020-15216
- EPSS 0.21%
- Veröffentlicht 29.09.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:05:06
In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users...
CVE-2020-26120
- EPSS 0.28%
- Veröffentlicht 27.09.2020 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:19:17
XSS exists in the MobileFrontend extension for MediaWiki before 1.34.4 because section.line is mishandled during regex section line replacement from PageGateway. Using crafted HTML, an attacker can elicit an XSS attack via jQuery's parseHTML method, ...
CVE-2020-26121
- EPSS 0.16%
- Veröffentlicht 27.09.2020 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:19:17
An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protected against "page creation" and the attacker should not be able to create it. This occurs because of a...
CVE-2020-25812
- EPSS 0.37%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:49
An issue was discovered in MediaWiki 1.34.x before 1.34.4. On Special:Contributions, the NS filter uses unescaped messages as keys in the option key for an HTMLForm specifier. This is vulnerable to a mild XSS if one of those messages is changed to in...
CVE-2020-25813
- EPSS 0.37%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:49
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users.
CVE-2020-25814
- EPSS 0.34%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:49
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related to jQuery can occur. The attacker creates a message with [javascript:payload xss] and turns it into a jQuery object with mw.message().parse(). The expected result is tha...
CVE-2020-25815
- EPSS 0.39%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:49
An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The relevant code should use escaped() instead of text().
CVE-2020-25827
- EPSS 0.24%
- Veröffentlicht 27.09.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:51
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limiting of OATH tokens is only done on a single site le...