An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or their differences were viewable) to unprivileged users, thus disclosing potentially sensitive information.
References
Link | Resource |
---|---|
https://gerrit.wikimedia.org/r/q/Ie23e8234ae550273bf3f6f9c5ac45b7fc54eec2a | Patch Vendor Advisory |
https://phabricator.wikimedia.org/T104807 | Patch Vendor Advisory |
https://gerrit.wikimedia.org/r/q/Ie23e8234ae550273bf3f6f9c5ac45b7fc54eec2a | Patch Vendor Advisory |
https://phabricator.wikimedia.org/T104807 | Patch Vendor Advisory |
Configurations
History
21 Nov 2024, 04:33
Type | Values Removed | Values Added |
---|---|---|
References | () https://gerrit.wikimedia.org/r/q/Ie23e8234ae550273bf3f6f9c5ac45b7fc54eec2a - Patch, Vendor Advisory | |
References | () https://phabricator.wikimedia.org/T104807 - Patch, Vendor Advisory |
Information
Published : 2019-10-29 19:15
Updated : 2024-11-21 04:33
NVD link : CVE-2019-18612
Mitre link : CVE-2019-18612
CVE.ORG link : CVE-2019-18612
JSON object : View
Products Affected
mediawiki
- abusefilter
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor