CVE-2021-30152 PUBLISHED

An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently have permissions for.

EPSS 0.53% · 66.8th percentile

Risk Scores

EPSS Score
0.53%
66.8th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSmediawiki0, 1:1.39.7-1, 1:1.39.6-1
Ubuntu:25.10mediawiki1:1.43.1+dfsg-2, 1:1.43.1+dfsg-1, 0
Ubuntu:20.04:LTSmediawiki0, 1:1.31.2-1ubuntu1, 1:1.31.5-1
Ubuntu:22.04:LTSmediawiki1:1.35.6-1, 1:1.35.5-1ubuntu3, 1:1.35.5-1ubuntu2
Ubuntu:18.04:LTSmediawiki1:1.27.4-3, 0, 1:1.27.3-1

Timeline

References

Open in Interactive Console →