CVE-2012-4380

HIGH

MediaWiki < 1.18.5 and 1.19.x < 1.19.2 - GlobalBlocking Extension IP Address Blocking Bypass

Title source: llm
STIX 2.1

Description

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an account via unspecified vectors.

References (6)

Core 6
Core References
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/08/31/6
Patch, Vendor Advisory mailing-list x_refsource_mlist
https://lists.wikimedia.org/pipermail/mediawiki-announce/2012-August/000119.html
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/08/31/10
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=853440
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=686330
Issue Tracking, Vendor Advisory x_refsource_confirm
https://phabricator.wikimedia.org/T41824

Scores

CVSS v3 7.5
EPSS 0.0055
EPSS Percentile 68.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-284
Status published
Products (3)
mediawiki/mediawiki 1.19.0
mediawiki/mediawiki 1.19.1
mediawiki/mediawiki < 1.18.4
Published Oct 19, 2017
Tracked Since Feb 18, 2026