VOOZH about

URL: https://github.com/advisories/GHSA-2qrr-c2gh-pr35

⇱ Wikimedia information leak vulnerability · CVE-2019-12474 · GitHub Advisory Database · GitHub


Skip to content

Wikimedia information leak vulnerability

High severity GitHub Reviewed Published to the GitHub Advisory Database • Updated

Package

mediawiki/core (Composer)

Affected versions

>= 1.27.0, < 1.27.6
>= 1.30.0, < 1.30.2
>= 1.31.0, < 1.31.2
>= 1.32.0, < 1.32.2

Patched versions

1.27.6
1.30.2
1.31.2
1.32.2

Description

Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

References

Published to the GitHub Advisory Database
Last updated
Reviewed

Severity

High
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS score

(79th percentile)

Weaknesses

CVE ID

CVE-2019-12474

GHSA ID

GHSA-2qrr-c2gh-pr35

Source code

See something to contribute? Suggest improvements for this vulnerability.
You can’t perform that action at this time.