CVE-2020-29007
Last modified
CVE-2020-29007 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted {{Image data to generate musical scores containing malicious code.. EPSS estimates a 2.32% chance of exploitation in the next 30 days.
Description
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted {{Image data to generate musical scores containing malicious code.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mediawiki | Score | <= 0.3.0 |
References
- https://github.com/seqred-s-a/cve-2020-29007Exploit, Mitigation, Third Party Advisory
- https://phabricator.wikimedia.org/T257062Exploit, Third Party Advisory
- https://seqred.pl/en/cve-2020-29007-remote-code-execution-in-mediawiki-score/Exploit, Third Party Advisory
- https://www.mediawiki.org/wiki/Extension:ScoreVendor Advisory
- https://github.com/seqred-s-a/cve-2020-29007Exploit, Mitigation, Third Party Advisory
- https://phabricator.wikimedia.org/T257062Exploit, Third Party Advisory
- https://seqred.pl/en/cve-2020-29007-remote-code-execution-in-mediawiki-score/Exploit, Third Party Advisory
- https://www.mediawiki.org/wiki/Extension:ScoreVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-29007?
How severe is CVE-2020-29007?
How do I fix CVE-2020-29007?
Are you affected by CVE-2020-29007?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
