Page MenuHomePhabricator

Obtain CVEs for 1.31.9/1.34.3/1.35.0 security releases
Closed, ResolvedPublic

Related Objects

Event Timeline

Reedy renamed this task from Obtain CVEs for 1.31.9/1.34.3 security releases to Obtain CVEs for 1.31.9/1.34.3/1.35.1 security releases.Aug 26 2020, 4:04 PM
Reedy renamed this task from Obtain CVEs for 1.31.9/1.34.3/1.35.1 security releases to Obtain CVEs for 1.31.9/1.34.3/1.35.0 security releases.Sep 21 2020, 2:39 PM

I feel like T260485: CentralAuth uses wrong actor ID when locally suppressing the user (CVE-2020-25869) should probably get a CVE since it can lead to Vuln-Infoleak and I feel like we've requested CVEs for most suppression-related issues in the past, or at least I have. I was also tracking this under T256342.

For the supplemental ext/skins, I think that just leaves T262213: XSS on Pages viewed on Mobile (CVE-2020-26120) and T262628: FileImporter imports the file even when the target page is protected on Commons and the importer should not be able to create it (CVE-2020-26121). T262724: Push extension exposes login credentials (CVE-2020-29004, CVE-2020-29005) is still kind of wandering through the æther - I need to follow up on that one. If the patch doesn't get merged soon, it'll likely have to wait until the next supplemental announcement. And I think T263498: Logins to MW with at least one SSO client extension allows masquerading as another user (CVE-2020-35623) will for sure have to wait for the next supplemental announcement.

I feel like T260485: CentralAuth uses wrong actor ID when locally suppressing the user (CVE-2020-25869) should probably get a CVE since it can lead to Vuln-Infoleak and I feel like we've requested CVEs for most suppression-related issues in the past, or at least I have. I was also tracking this under T256342.

I've requested a CVE for that too now

Reedy claimed this task.
Reedy triaged this task as Medium priority.
Reedy changed the visibility from "acl*security (Project)" to "Public (No Login Required)".
Reedy changed the edit policy from "acl*security (Project)" to "All Users".