HIGH
Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak
Published Jul 10, 2019
7.5
HIGHCVSS 3.0
EPSS 2.04%
Description
Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://github.com/FriendsOfPHP/security-advisories/blob/master/mediawiki/core/CVE-2019-12474.yaml
- https://github.com/advisories/GHSA-2qrr-c2gh-pr35 Advisory
- https://lists.wikimedia.org/pipermail/wikitech-l/2019-June/092152.html x_refsource_CONFIRMPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-12474
- https://phabricator.wikimedia.org/T212118 x_refsource_MISCPatchThird Party Advisory
- https://seclists.org/bugtraq/2019/Jun/12 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://www.debian.org/security/2019/dsa-4460 vendor-advisoryx_refsource_DEBIANThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/FriendsOfPHP/security-advisories/blob/master/mediawiki/core/CVE-2019-12474.yaml | ||
| https://github.com/advisories/GHSA-2qrr-c2gh-pr35 | Advisory | |
| https://lists.wikimedia.org/pipermail/wikitech-l/2019-June/092152.html | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-12474 | ||
| https://phabricator.wikimedia.org/T212118 | x_refsource_MISCPatchThird Party Advisory | |
| https://seclists.org/bugtraq/2019/Jun/12 | mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory | |
| https://www.debian.org/security/2019/dsa-4460 | vendor-advisoryx_refsource_DEBIANThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 10, 2019
Updated Aug 4, 2024
Reserved May 30, 2019
Link CVE-2019-12474
CISA Vulnrichment
GHSA-2QRR-C2GH-PR35 Updated n/a