CVE-2010-2787
EPSS 0.55%
Description
api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.
How to fix CVE-2010-2787
To remediate CVE-2010-2787, upgrade the affected package to a fixed version below.
- Debian/mediawiki—upgrade to 1:1.15.5-1 or later
Is CVE-2010-2787 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1:1.15.5-1