Description
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.
Remediation
References
Related Vulnerabilities
WordPress Plugin InfiniteWP Client Unspecified Vulnerability (1.3.14)
Apache Traffic Server CVE-2015-5206 Vulnerability (CVE-2015-5206)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-5014)
WordPress Plugin Classified Listing Pro & Directory Cross-Site Scripting (2.0.19)