关键漏洞信息 漏洞详情 1. Stored XSS via a File::link to a non-existing image - Upstream Bug: Bugzilla - Patches: 1.19 Version, 1.18 Version - References: Various forums and bug reports 2. Multiple DOM-based XSS flaws due to improper filtering of uselang parameter - Upstream Bug: Bugzilla - Patch: Gerrit - References: Debian bug reports, Red Hat bugzilla 3. CSRF tokens, available via API, not protected when X-Frame-Options headers used - Upstream Bug: Bugzilla - Patch: Gerrit - References: Debian bug reports, Red Hat bugzilla 4. Did not prevent account creation for IP addresses blocked with GlobalBlocking - Upstream Bug: Bugzilla - 1.18 Version Patch: Bugzilla - References: Debian bug reports, Red Hat bugzilla 5. Password saved always to the local MediaWiki database and possibility to use old passwords for non-existing accounts in the external auth system - Upstream Bug: Bugzilla - Patch: Bugzilla - References: Debian bug reports, Red Hat bugzilla 6. Metadata about blocks, hidden by a user with suppression rights, was visible to administrators - Upstream Bug: Bugzilla - 1.18 Branch Patch: Bugzilla - References: Various forums and bug reports 其他信息 CVE IDs: 请求分配CVE编号 感谢: Jan Lieskovsky, Red Hat Security Response Team