Candidate: CVE-2016-6335 PublicDate: 2017-04-20 17:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6335 https://lists.wikimedia.org/pipermail/wikitech-l/2016-August/086342.html Description: MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of a given title, which allows remote attackers to obtain sensitive information via a parse action to api.php. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_mediawiki: upstream_mediawiki: released (1.27.1,1.26.4,1.23.15) precise_mediawiki: ignored (reached end-of-life) precise/esm_mediawiki: DNE (precise was needed) trusty_mediawiki: ignored (reached end-of-life) trusty/esm_mediawiki: DNE (trusty was needed) vivid/stable-phone-overlay_mediawiki: DNE vivid/ubuntu-core_mediawiki: DNE xenial_mediawiki: DNE yakkety_mediawiki: ignored (reached end-of-life) zesty_mediawiki: ignored (reached end-of-life) artful_mediawiki: ignored (reached end-of-life) bionic_mediawiki: not-affected (1.27.1) cosmic_mediawiki: not-affected (1.27.1) disco_mediawiki: not-affected (1.27.1) devel_mediawiki: not-affected (1.27.1)