An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or their differences were viewable) to unprivileged users, thus disclosing potentially sensitive information.
References
Link | Resource |
---|---|
https://gerrit.wikimedia.org/r/q/Ie23e8234ae550273bf3f6f9c5ac45b7fc54eec2a | Patch Vendor Advisory |
https://phabricator.wikimedia.org/T104807 | Patch Vendor Advisory |
Configurations
Information
Published : 2019-10-29 12:15
Updated : 2019-10-31 05:09
NVD link : CVE-2019-18612
Mitre link : CVE-2019-18612
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
mediawiki
- abusefilter