Unrated severityNVD Advisory· Published Sep 9, 2012· Updated Apr 29, 2026
CVE-2012-1579
CVE-2012-1579
Description
The resource loader in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 includes private data such as CSRF tokens in a JavaScript file, which allows remote attackers to obtain sensitive information.
Affected products
11cpe:2.3:a:mediawiki:mediawiki:1.17:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:mediawiki:mediawiki:1.17:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.17.0:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.17.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.17.1:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.17.2:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.17:beta_1:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.18:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.18.0:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.18.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.18.1:*:*:*:*:*:*:*
- cpe:2.3:a:mediawiki:mediawiki:1.18:beta_1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- bugzilla.wikimedia.org/show_bug.cginvdExploit
- lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000109.htmlnvdVendor Advisory
- lists.wikimedia.org/pipermail/mediawiki-announce/2012-March/000110.htmlnvdVendor Advisory
- secunia.com/advisories/48504nvdVendor Advisory
- www.openwall.com/lists/oss-security/2012/03/22/9nvd
- www.openwall.com/lists/oss-security/2012/03/24/1nvd
- www.securityfocus.com/bid/52689nvd
News mentions
0No linked articles in our index yet.