CVE-2022-39193

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension can expose information on the performer of edits and logged actions. This information should not allow public viewing: it is supposed to be viewable only by users with checkuser access.
References
Link Resource
https://phabricator.wikimedia.org/T311337 Exploit Issue Tracking Patch Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mediawiki:mediawiki:1.39.0:rc0:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.39.0:rc1:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.39.0:-:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.39.1:*:*:*:*:*:*:*

Information

Published : 2023-01-20 11:15

Updated : 2023-02-02 08:55


NVD link : CVE-2022-39193

Mitre link : CVE-2022-39193


JSON object : View

CWE
CWE-668

Exposure of Resource to Wrong Sphere

Advertisement

dedicated server usa

Products Affected

mediawiki

  • mediawiki