{"id":"GHSA-xpv7-93cm-4mxv","summary":"img_auth.php may leak private extension images into the public cache","details":"In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.","aliases":["BIT-mediawiki-2020-15005","CVE-2020-15005"],"modified":"2024-12-02T05:43:08.647397Z","published":"2022-05-24T17:21:40Z","database_specific":{"github_reviewed_at":"2024-11-01T23:09:01Z","github_reviewed":true,"nvd_published_at":"2020-06-24T23:15:00Z","cwe_ids":["CWE-200"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15005"},{"type":"WEB","url":"https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/core/+/REL1_31/RELEASE-NOTES-1.31"},{"type":"WEB","url":"https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/core/+/REL1_33/RELEASE-NOTES-1.33"},{"type":"WEB","url":"https://gerrit.wikimedia.org/r/plugins/gitiles/mediawiki/core/+/REL1_34/RELEASE-NOTES-1.34"},{"type":"PACKAGE","url":"https://github.com/wikimedia/mediawiki"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2020/12/msg00034.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EEZIMLJMJS72SJXPYL736XMUAVCRQD2H"},{"type":"WEB","url":"https://lists.wikimedia.org/pipermail/wikitech-l/2020-June/093535.html"},{"type":"WEB","url":"https://phabricator.wikimedia.org/T248947"},{"type":"WEB","url":"https://www.debian.org/security/2020/dsa-4767"}],"affected":[{"package":{"name":"mediawiki/core","ecosystem":"Packagist","purl":"pkg:composer/mediawiki/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.31.8"}]}],"versions":["1.20.3","1.20.4","1.20.5","1.20.6","1.20.7","1.20.8","1.21.0","1.21.1","1.21.10","1.21.11","1.21.2","1.21.3","1.21.4","1.21.5","1.21.6","1.21.7","1.21.8","1.21.9","1.22.0rc0","1.24.0","1.24.0-rc.0","1.24.0-rc.1","1.24.0-rc.2","1.24.0-rc.3","1.24.1","1.24.2","1.24.3","1.24.4","1.24.5","1.24.6","1.25.0","1.25.0-rc.0","1.25.1","1.25.2","1.25.3","1.25.4","1.25.5","1.25.6","1.26.0","1.26.1","1.26.2","1.26.3","1.26.4","1.27.0","1.27.0-rc.0","1.27.0-rc.1","1.27.1","1.27.2","1.27.3","1.27.4","1.27.5","1.27.6","1.27.7","1.28.0","1.28.0-rc.0","1.28.0-rc.1","1.28.1","1.28.2","1.28.3","1.29.0","1.29.0-rc.0","1.29.0-rc.1","1.29.1","1.29.2","1.29.3","1.30.0","1.30.0-rc.0","1.30.1","1.30.2","1.31.0","1.31.0-rc.0","1.31.0-rc.1","1.31.0-rc.2","1.31.1","1.31.2","1.31.3","1.31.4","1.31.5","1.31.6","1.31.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xpv7-93cm-4mxv/GHSA-xpv7-93cm-4mxv.json"}},{"package":{"name":"mediawiki/core","ecosystem":"Packagist","purl":"pkg:composer/mediawiki/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.32.0"},{"fixed":"1.33.4"}]}],"versions":["1.32.0","1.32.1","1.32.2","1.32.3","1.32.4","1.32.5","1.32.6","1.33.0","1.33.0-rc.0","1.33.1","1.33.2","1.33.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xpv7-93cm-4mxv/GHSA-xpv7-93cm-4mxv.json"}},{"package":{"name":"mediawiki/core","ecosystem":"Packagist","purl":"pkg:composer/mediawiki/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.34.0"},{"fixed":"1.34.2"}]}],"versions":["1.34.0","1.34.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xpv7-93cm-4mxv/GHSA-xpv7-93cm-4mxv.json"}}],"schema_version":"1.7.3"}