CVE-2017-0371
Linux Debian vulnerability analysis and mitigation

Overview

MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 contains a vulnerability that allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute (Wikimedia Phabricator).

Technical details

The vulnerability exists in the CSS sanitizer functionality. The sanitizer rejects any inline CSS with "url(" to prevent web bugs, but a proposed update to attr() would allow circumvention of this check. The attack involves creating a span with a URL as title, where the inline CSS then adds a background image defined by that title interpreted as URL, enabling image loading from any domain (Wikimedia Phabricator).

Impact

If exploited, this vulnerability allows attackers to track Wiki visitors by discovering their IP addresses through web bug techniques. This represents a privacy concern as it enables unauthorized tracking of users visiting Wiki pages (Wikimedia Phabricator).

Mitigation and workarounds

The issue was fixed in MediaWiki versions 1.23.16, 1.27.2, and 1.28.1. Users should upgrade to these versions or later to protect against this vulnerability. The fix involves rejecting CSS attr() with URL type in the sanitizer (Wikimedia Phabricator).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-67858N/AN/A
  • Linux DebianLinux Debian
  • foomuuri
NoYesJan 08, 2026
CVE-2025-67603N/AN/A
  • Linux DebianLinux Debian
  • foomuuri
NoYesJan 08, 2026
CVE-2025-14017N/AN/A
  • cURLcURL
  • curl
NoYesJan 08, 2026
CVE-2025-15224N/AN/A
  • cURLcURL
  • curl
NoYesJan 06, 2026
CVE-2025-15079N/AN/A
  • cURLcURL
  • curl
NoYesJan 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management