X-Forwarded-For Header Vulnerability in MediaWiki by Wikimedia
CVE-2023-29141

9.8CRITICAL

Key Information:

Vendor

Mediawiki

Status
Vendor
CVE Published:
31 March 2023

What is CVE-2023-29141?

A vulnerability exists in MediaWiki that allows for potential auto-blocks due to the mishandling of an untrusted X-Forwarded-For header. This can lead to unintended restrictions on legitimate users, impacting service accessibility. The issue affects multiple versions of MediaWiki and emphasizes the necessity for proper validation of incoming request headers.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.