DEBIAN-CVE-2023-45360

Source
https://security-tracker.debian.org/tracker/DEBIAN-CVE-2023-45360
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-45360.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2023-45360
Upstream
Published
2023-11-03T05:15:30Z
Modified
2025-09-19T07:33:28.196031Z
Summary
[none]
Details

An issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenewmessagesmanyusers and youhavenewmessages i18n messages. This is related to MediaWiki:Youhavenewmessagesfromusers.

References

Affected packages

Debian:11 / mediawiki

Package

Name
mediawiki
Purl
pkg:deb/debian/mediawiki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.35.13-1~deb11u1

Affected versions

1:1.*

1:1.35.2-1
1:1.35.3-1
1:1.35.4-1~deb11u1
1:1.35.4-1
1:1.35.4-1+deb11u2
1:1.35.5-1
1:1.35.5-2
1:1.35.6-1
1:1.35.7-1
1:1.35.8-1~deb11u1
1:1.35.8-1
1:1.35.8-1.1
1:1.35.11-1~deb11u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / mediawiki

Package

Name
mediawiki
Purl
pkg:deb/debian/mediawiki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.39.5-1~deb12u1

Affected versions

1:1.*

1:1.39.2-1
1:1.39.4-1~deb12u1
1:1.39.4-1
1:1.39.4-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / mediawiki

Package

Name
mediawiki
Purl
pkg:deb/debian/mediawiki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.39.5-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / mediawiki

Package

Name
mediawiki
Purl
pkg:deb/debian/mediawiki?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.39.5-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}