Description
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.
Published: 2020-02-06
Score: 7.5 High
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-2891-1 mediawiki security update
Debian DSA Debian DSA DSA-2891-2 mediawiki regression update
Debian DSA Debian DSA DSA-2891-3 mediawiki regression update
EUVD EUVD EUVD-2013-4430 The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00849}

epss

{'score': 0.01163}


Subscriptions

Fedoraproject Fedora
Mediawiki Mediawiki
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T16:45:15.240Z

Reserved: 2013-06-12T00:00:00.000Z

Link: CVE-2013-4572

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-02-06T15:15:10.387

Modified: 2024-11-21T01:55:51.343

Link: CVE-2013-4572

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses