oss-sec mailing list archives
Re: CVE request: Mediawiki before 1.19.20, 1.22.12, 1.23.5 XSS through CSS
From: cve-assign () mitre org
Date: Thu, 2 Oct 2014 13:05:13 -0400 (EDT)
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-October/000163.html https://bugzilla.wikimedia.org/show_bug.cgi?id=70672 (bug 70672) SECURITY: OutputPage: Remove separation of css and js module allowance. https://gerrit.wikimedia.org/r/#/c/164271/
No longer segment module origin allowance
It seems best to assign only one CVE ID for the availability of CSS in an apparently unintended context, with resultant impacts of both XSS and UI redressing. Use CVE-2014-7295.
While at it, also remove the ability to set the module allowance directly.
This change seems to be about eliminating unused and possibly confusing functionality, not a separate vulnerability fix. - -- CVE assignment team, MITRE CVE Numbering Authority M/S M300 202 Burlington Road, Bedford, MA 01730 USA [ PGP key available through http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (SunOS) iQEcBAEBAgAGBQJULYVrAAoJEKllVAevmvms9wMH/0z2JxQOGiKWh6m7opKgeBEK Z/9hLV0dmmLdXGnBo2o3HK/J0h1bYklT6+TEdQ1ESJ4EIHlejB7WsUnQY4XlSlzA LtqFxRIBhbwVOdv+UGgdZXfNGaPoMflZqa1KSYa6vb9rIxoc3CPglM/59qSc6XCN 3Xr3mu8E9fbNT7YsZeatVhzxUh6QYHJ5JpOx7z/xiwGNqZfDqqb/eh4p70FcVPY6 bsykRXmmOwLIujsn47gSCW+g383F4vTFj7AyhIDahZXOWbm4hwJJWG6mi/MWsd3L /nIfzN6UQfSu6EFuMLDg1+/qfJPWi9kzal/XtTG3zu54DKRqedn5UZ/EdxzrbGE= =iYhQ -----END PGP SIGNATURE-----
Current thread:
- CVE request: Mediawiki before 1.19.20, 1.22.12, 1.23.5 XSS through CSS Hanno Böck (Oct 02)
- Re: CVE request: Mediawiki before 1.19.20, 1.22.12, 1.23.5 XSS through CSS cve-assign (Oct 02)