CVE-2014-2665

Publication date 20 April 2014

Last updated 24 July 2024


Ubuntu priority

includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x before 1.22.5 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker’s account, as demonstrated by tracking the victim’s activity, related to a “login CSRF” issue.

Status

Package Ubuntu Release Status
mediawiki 17.04 zesty
Not affected
16.10 yakkety
Not affected
16.04 LTS xenial Not in release
15.10 wily
Not affected
15.04 vivid
Not affected
14.10 utopic
Not affected
14.04 LTS trusty Not in release
13.10 saucy Ignored end of life
12.10 quantal Ignored end of life
12.04 LTS precise Ignored end of life
10.04 LTS lucid Ignored end of life