CVE-2022-29903
NixOS vulnerability analysis and mitigation

Overview

The Private Domains extension for MediaWiki through version 1.37.2 (before commit 1ad65d4c1c19) contained a Cross-Site Request Forgery (CSRF) vulnerability that affected the page editing functionality (NVD).

Technical details

The vulnerability existed in the Special:PrivateDomains form which allowed editing pages in NS_MEDIAWIKI namespace used for storing PrivateDomains settings. The form lacked proper anti-CSRF token implementation, only verifying that the request was POSTed and the action was 'submit' without any CSRF protection (Phabricator).

Impact

An attacker could potentially trick authenticated users into making unwanted changes to the PrivateDomains settings through CSRF attacks, effectively modifying the extension's configuration without the user's knowledge or consent (Phabricator).

Mitigation and workarounds

The vulnerability was fixed by adding proper anti-CSRF token validation to the edit form. Users should upgrade to a version after commit 1ad65d4c1c19, which implements the security fix by adding wpEditToken validation (Phabricator).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-20807MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2025-20806MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2025-20805MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2025-20804MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2025-20803MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management