An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information for log events. (The log_deleted attribute is not respected.)
References
| Link | Resource |
|---|---|
| https://phabricator.wikimedia.org/T326865 | Issue Tracking Vendor Advisory |
| https://phabricator.wikimedia.org/T326865 | Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-07-07 00:15
Updated : 2025-06-17 20:16
NVD link : CVE-2024-40597
Mitre link : CVE-2024-40597
CVE.ORG link : CVE-2024-40597
JSON object : View
Products Affected
mediawiki
- mediawiki
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
