vulnerability

FreeBSD: VID-466ba8bd-d033-11ed-addf-080027eda32c (CVE-2020-36649): mediawiki -- multiple vulnerabilities

Severity
2
CVSS
(AV:A/AC:M/Au:S/C:N/I:N/A:P)
Published
Apr 1, 2023
Added
Apr 14, 2023
Modified
Dec 10, 2025

Description

Mediawikwi reports: (T285159, CVE-2023-PENDING) SECURITY: X-Forwarded-For header allows brute-forcing autoblocked IP addresses. (T326946, CVE-2020-36649) SECURITY: Bundled PapaParse copy in VisualEditor has known ReDos. (T330086, CVE-2023-PENDING) SECURITY: OATHAuth allows replay attacks when MediaWiki is configured without ObjectCache; Insecure Default Configuration.

Solutions

freebsd-upgrade-package-mediawiki135freebsd-upgrade-package-mediawiki138freebsd-upgrade-package-mediawiki139
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.