Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2891-1 | mediawiki security update |
Debian DSA |
DSA-2891-2 | mediawiki regression update |
Debian DSA |
DSA-2891-3 | mediawiki regression update |
EUVD |
EUVD-2013-4430 | The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user. |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T16:45:15.240Z
Reserved: 2013-06-12T00:00:00.000Z
Link: CVE-2013-4572
No data.
Status : Modified
Published: 2020-02-06T15:15:10.387
Modified: 2026-06-16T23:57:28.543
Link: CVE-2013-4572
No data.
OpenCVE Enrichment
No data.
-
CWE-384
Session Fixation
Debian DSA
EUVD