MediaWiki standalone "readers" can also edit pages
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 14.2.99.148
Patched versions
14.2.99.148
Tuleap Enterprise Edition
(tuleap)
>= 14.2-1 && < 14.2.-5
< 14.1-6
14.2-5
14.1-6
Authorizations are not properly verified when accessing to MediaWiki standalone resources.
Impact
Users with only the ability to read pages can also edit them. This only affects the MediaWiki standalone plugin.
Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References