Candidate: CVE-2012-1579 PublicDate: 2012-09-09 21:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1579 http://www.openwall.com/lists/oss-security/2012/03/23 Description: The resource loader in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 includes private data such as CSRF tokens in a JavaScript file, which allows remote attackers to obtain sensitive information. Ubuntu-Description: Notes: micahg> Debian maintainer said 1.15 isn't affected, see 1:1.15.5-9 changelog Bugs: https://bugzilla.wikimedia.org/show_bug.cgi?id=34907 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_mediawiki: upstream_mediawiki: needs-triage hardy_mediawiki: ignored (reached end-of-life) lucid_mediawiki: not-affected (1.15.x) maverick_mediawiki: ignored (reached end-of-life) natty_mediawiki: not-affected (1.15.x) oneiric_mediawiki: not-affected (1.15.x) precise_mediawiki: not-affected (1.15.x) quantal_mediawiki: not-affected (1.15.x) raring_mediawiki: not-affected (1.15.x) devel_mediawiki: not-affected (1.15.x)