CVE-2019-12474Sensitive Information Exposure in Mediawiki

Severity
7.5HIGHNVD
EPSS
0.3%
top 50.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10
Latest updateMay 24

Description

Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

Packagistmediawiki/core1.27.01.27.6+3
debiandebian/mediawiki< mediawiki 1:1.31.2-1 (bookworm)
NVDmediawiki/mediawiki1.23.01.27.6+3
Debianmediawiki/mediawiki< 1:1.31.2-1+3

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

3
OSV
Wikimedia information leak vulnerability2022-05-24
GHSA
Wikimedia information leak vulnerability2022-05-24
OSV
CVE-2019-12474: Wikimedia MediaWiki 12019-07-10

📋Vendor Advisories

1
Debian
CVE-2019-12474: mediawiki - Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged AP...2019
CVE-2019-12474 — Sensitive Information Exposure | cvebase