|
Message-ID: <CAKcmtDwm9Kt6eHrKX1UY2bqc26VFwpESZq2Ui5TtZxMuTgbhww@mail.gmail.com> Date: Thu, 27 Mar 2014 18:37:56 -0700 From: Chris Steipp <csteipp@...imedia.org> To: oss-security@...ts.openwall.com Subject: CVE request: MediaWiki 1.22.5 login csrf Hi, we just patched a login CSRF in MediaWiki today. An attacker could login a victim as the attacker. Can we get a cve assigned for this? Patch: https://gerrit.wikimedia.org/r/#/c/121517/1/includes/specials/SpecialChangePassword.php Release announcement: http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-March/000145.html Wikimedia bug: https://bugzilla.wikimedia.org/show_bug.cgi?id=62497
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.