T248947: img_auth.php may leak private extension images into the public cache (CVE-2020-15005): In MediaWiki before 1.31.8/1.33.4/1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. All MediaWiki versions since 1.23.0 are vulnerable.
Description
Description
| Status | Subtype | Assigned | Task | ||
|---|---|---|---|---|---|
| Resolved | Reedy | T248534 Release MediaWiki 1.31.8/1.33.4/1.34.2 | |||
| Resolved | Legoktm | T248541 Obtain CVEs for 1.31.8/1.33.4/1.34.2 security releases |