CVE-2013-4572: Fedoraproject Fedora

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.

Affected products

  • Fedoraproject Fedora: version 18 only; version 19 only
  • Mediawiki Mediawiki: before 1.19.9 (fixed in 1.19.9); from 1.20, before 1.20.8 (fixed in 1.20.8); from 1.21, before 1.21.3 (fixed in 1.21.3)

Published 2020-02-06. Last modified 2026-06-16.