| Reedy |
| Dec 10 2019, 10:53 PM |
| F31700300: 0002-T232932-master.patch |
| Mar 24 2020, 5:03 PM |
| F31700299: 0001-T246602-master.patch |
| Mar 24 2020, 5:03 PM |
Description
Previous work T233495: Tracking bug for MediaWiki 1.31.6/1.32.6/1.33.2/1.34.0 security release
Tracking bug for next security release
| Maniphest ID | CVE ID | REL1_31 | REL1_33 | REL1_34 | master |
|---|---|---|---|---|---|
| T232932 | CVE-2020-10959 | n/a | n/a | 0002-T232932-master.patch2 KBDownload | |
| T246602 | CVE-2020-10960 | 0001-T246602-master.patch1 KBDownload |
n.b. T246602 is a pretty minor issue, but should probably be included here anyways.
Related Objects
| Status | Subtype | Assigned | Task | ||
|---|---|---|---|---|---|
| Resolved | Reedy | T240392 Release MediaWiki 1.31.7/1.33.3/1.34.1 | |||
| Resolved | Reedy | T240393 Tracking bug for MediaWiki 1.31.7/1.33.3/1.34.1 | |||
| Resolved | sbassett | T232932 User content can redirect the logout button to different URL (CVE-2020-10959) | |||
| Resolved | Security | sbassett | T246602 makeCollapsible allows applying event handler to any CSS selector (CVE-2020-10960) |
- Mentioned In
- T248535: Tracking bug for MediaWiki 1.31.8/1.33.4/1.34.2
T240399: Obtain CVEs for 1.31.7/1.33.3/1.34.1 security releases
T234104: PageTriage: Api allows spamming users with notifications
T229731: Global blocks: if an IP is within two ranges and one is locally disabled, GlobalBlock won't listen to the other one (CVE-2020-10534)
T239466: Possible to circumvent title-blacklist (CVE-2019-19709) - Mentioned Here
- T246602: makeCollapsible allows applying event handler to any CSS selector (CVE-2020-10960)
T229731: Global blocks: if an IP is within two ranges and one is locally disabled, GlobalBlock won't listen to the other one (CVE-2020-10534)
T232932: User content can redirect the logout button to different URL (CVE-2020-10959)
T239466: Possible to circumvent title-blacklist (CVE-2019-19709)
T233495: Tracking bug for MediaWiki 1.31.6/1.32.6/1.33.2/1.34.0 security release
Event Timeline
CVEs requested. Will update table in task description and task titles when I have the IDs.
@Reedy I've hidden this again - T232932: User content can redirect the logout button to different URL (CVE-2020-10959) still isn't public (I can't see it) but the fact that the patch file is included here means that the patch can be viewed by anyone who can see this task, which probably wasn't supposed to be public. If it was, apologies for overreacting
In T240393#6002789, @DannyS712 wrote:@Reedy I've hidden this again - T232932: User content can redirect the logout button to different URL (CVE-2020-10959) still isn't public (I can't see it) but the fact that the patch file is included here means that the patch can be viewed by anyone who can see this task, which probably wasn't supposed to be public. If it was, apologies for overreacting
Considering the patch is already listed on https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-March/000247.html...
