MEDIUM
mediawiki: suppressed username information disclosure via Special:Redirect
Published Sep 26, 2019
5.3
MEDIUMCVSS 3.1
EPSS 1.77%
Description
In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.
Affected products
No data.
Configuration 1
Configuration 2
OR
- 30
- 31
Configuration 3
OR
- 9.0
- 10.0
No data.
Red Hat OpenShift Container Platform 3.10
mediawiki
Out of support scope
Red Hat OpenShift Container Platform 3.11
mediawiki
Will not fix
Red Hat OpenShift Container Platform 3.9
mediawiki123
Out of support scope
Red Hat OpenShift Container Platform 4
mediawiki
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.10 | mediawiki | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | mediawiki | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.9 | mediawiki123 | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | mediawiki | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2019-16738 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1755762 Issue Tracking
- https://github.com/FriendsOfPHP/security-advisories/blob/master/mediawiki/core/CVE-2019-16738.yaml
- https://github.com/advisories/GHSA-7hwr-f745-5rwq Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7OMG3BMUHGWTAPYTK2NXM6CXF6FYLOUO vendor-advisoryx_refsource_FEDORABroken Link
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QBAOLXETM5BOYQG6OQVHGB2LNLZUXVN6 vendor-advisoryx_refsource_FEDORABroken Link
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7OMG3BMUHGWTAPYTK2NXM6CXF6FYLOUO
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QBAOLXETM5BOYQG6OQVHGB2LNLZUXVN6
- https://nvd.nist.gov/vuln/detail/CVE-2019-16738
- https://phabricator.wikimedia.org/T230402 x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory
- https://seclists.org/bugtraq/2019/Oct/32 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-16738
- https://www.debian.org/security/2019/dsa-4545 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 26, 2019
Updated Aug 5, 2024
Reserved Sep 24, 2019
Link CVE-2019-16738
CISA Vulnrichment
GHSA-7HWR-F745-5RWQ Updated n/a