CVE-2020-15005

Publication date 24 June 2020

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

3.1 · Low

Score breakdown

In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.

Status

Package Ubuntu Release Status
mediawiki 25.04 plucky
Fixed 1:1.31.8-1
24.10 oracular
Fixed 1:1.31.8-1
24.04 LTS noble
Fixed 1:1.31.8-1
23.10 mantic
Fixed 1:1.31.8-1
23.04 lunar
Fixed 1:1.31.8-1
22.10 kinetic
Fixed 1:1.31.8-1
22.04 LTS jammy
Fixed 1:1.31.8-1
21.10 impish
Fixed 1:1.31.8-1
21.04 hirsute
Fixed 1:1.31.8-1
20.10 groovy
Fixed 1:1.31.8-1
20.04 LTS focal
Vulnerable
19.10 eoan Ignored end of life
18.04 LTS bionic
Vulnerable
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release

Severity score breakdown

Parameter Value
Base score 3.1 · Low
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality Low
Integrity impact None
Availability impact None
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N