[Git][security-tracker-team/security-tracker][master] Track fixed version for mediawiki issues fixed via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Oct 24 20:10:12 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
30d79454 by Salvatore Bonaccorso at 2025-10-24T21:09:37+02:00
Track fixed version for mediawiki issues fixed via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7541,20 +7541,20 @@ CVE-2025-61962 (In fetchmail before 6.5.6, the SMTP client can crash when authen
 	NOTE: https://www.fetchmail.info/fetchmail-SA-2025-01.txt
 	NOTE: Fixed by: https://gitlab.com/fetchmail/fetchmail/-/commit/4c3cebfa4e659fb778ca2cae0ccb3f69201609a8 (6.5.6)
 CVE-2025-61656 [Sanitize attributes unwrapped from data-ve-attributes]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	NOTE: https://phabricator.wikimedia.org/T397232
 	NOTE: https://gerrit.wikimedia.org/r/c/VisualEditor/VisualEditor/+/1193247
 CVE-2025-61655 [Properly escape and parse system messages]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	NOTE: https://phabricator.wikimedia.org/T395858
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/extensions/VisualEditor/+/1193248
 CVE-2025-61657 [Insert sticky header labels as text instead of HTML]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	[bookworm] - mediawiki <not-affected> (Vulnerable code not present)
 	[bullseye] - mediawiki <not-affected> (Vulnerable code not present)
 	NOTE: http://phabricator.wikimedia.org/T398636
 CVE-2025-61654 [Exclude deleted entries when counting thanks]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	[bookworm] - mediawiki <not-affected> (Vulnerable code not present)
 	[bullseye] - mediawiki <not-affected> (Vulnerable code not present)
 	NOTE: https://phabricator.wikimedia.org/T397497
@@ -7613,11 +7613,11 @@ CVE-2025-10895
 CVE-2025-10653 (An unauthenticated debug port may allow access to the device file syst ...)
 	NOT-FOR-US: Raise3D
 CVE-2025-61653 [Add authorizeRead check for extracts endpoint]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	NOTE: http://phabricator.wikimedia.org/T397577
 	NOTE: http://phabricator.wikimedia.org/T397577
 CVE-2025-11173
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	NOTE: https://phabricator.wikimedia.org/T401862
 	NOTE: https://phabricator.wikimedia.org/T402094
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/extensions/OATHAuth/+/1180998
@@ -7629,12 +7629,12 @@ CVE-2025-11175
 	NOTE: https://phabricator.wikimedia.org/T364910
 	NOTE: https://phabricator.wikimedia.org/T396248
 CVE-2025-61652 [In API check user read permissions before showing PageInfo]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	[bookworm] - mediawiki <not-affected> (Vulnerable code not present)
 	[bullseye] - mediawiki <not-affected> (Vulnerable code not present)
 	NOTE: https://phabricator.wikimedia.org/T397580
 CVE-2025-61635 [ApiFancyCaptchaReload: Reuse badcaptcha rate limit]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	NOTE: http://phabricator.wikimedia.org/T355073
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/extensions/ConfirmEdit/+/1193206
 CVE-2025-61648
@@ -7644,7 +7644,7 @@ CVE-2025-61658
 CVE-2025-61651
 	NOT-FOR-US: MediaWiki extension CheckUser
 CVE-2025-61646 [Prevent leaking hidden usernames in Watchlist/RecentChanges]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	NOTE: https://phabricator.wikimedia.org/T398706
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1193226
 CVE-2025-61645 [Fix i18n XSS in CodexTablePager]
@@ -7652,7 +7652,7 @@ CVE-2025-61645 [Fix i18n XSS in CodexTablePager]
 	NOTE: http://phabricator.wikimedia.org/T403761
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1193202
 CVE-2025-61643 [Don't send suppressed recent changes to RCFeeds]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	NOTE: https://phabricator.wikimedia.org/T403757
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1193223
 CVE-2025-61735 (Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin.  Thi ...)
@@ -7878,42 +7878,42 @@ CVE-2024-58267 (A vulnerability has been identified within Rancher Manager where
 CVE-2024-58260 (A vulnerability has been identified within Rancher Manager where a mis ...)
 	NOT-FOR-US: Rancher
 CVE-2025-61642 [Escape submit button label for Codex-based HTMLForms]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	[bookworm] - mediawiki <not-affected> (Vulnerable code not present)
 	[bullseye] - mediawiki <not-affected> (Vulnerable code not present)
 	NOTE: https://phabricator.wikimedia.org/T402313
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1193175
 CVE-2025-61641 [api: Disable maxsize in QueryAllPages in miser mode]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	NOTE: https://phabricator.wikimedia.org/T298690
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1193174
 CVE-2025-61640 [Parse messages instead of inserting them as HTML]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	NOTE: https://phabricator.wikimedia.org/T402075
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1193173
 CVE-2025-61639 [Use ManualLogEntry::getDeleted in ::getRecentChange]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	NOTE: https://phabricator.wikimedia.org/T280413
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1193178
 CVE-2025-61638 [Sanitize data- attributes]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	NOTE: https://phabricator.wikimedia.org/T401099
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1193172
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1193218
 CVE-2025-61637 [Escape three system messages used by live preview]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	[bookworm] - mediawiki <not-affected> (Vulnerable code not present)
 	[bullseye] - mediawiki <not-affected> (Vulnerable code not present)
 	NOTE: https://phabricator.wikimedia.org/T394856
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1193171
 CVE-2025-61636 [Escape rawElement $content]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	[bookworm] - mediawiki <not-affected> (Vulnerable code not present)
 	[bullseye] - mediawiki <not-affected> (Vulnerable code not present)
 	NOTE: https://phabricator.wikimedia.org/T394396
 	NOTE: https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1193170
 CVE-2025-61634 [REST: Set cache-control value of max-age=60 for redirects]
-	- mediawiki <unfixed>
+	- mediawiki 1:1.43.5+dfsg-1
 	[bookworm] - mediawiki <not-affected> (Redirect introduced in 1.40)
 	[bullseye] - mediawiki <not-affected> (Redirect introduced in 1.40)
 	NOTE: https://phabricator.wikimedia.org/T387478



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/30d79454be441f7b96affc59d3d8ed96b63eafec

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/30d79454be441f7b96affc59d3d8ed96b63eafec
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251024/9b918b6e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list