CVE-2019-16738Missing Authorization in Core

Severity
5.3MEDIUMNVD
EPSS
0.4%
top 38.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 26
Latest updateMay 24

Description

In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

Packagistmediawiki/core1.31.01.31.4+2
debiandebian/mediawiki< mediawiki 1:1.31.4-1 (bookworm)
Debianmediawiki/mediawiki< 1:1.31.4-1+3

Also affects: Debian Linux 10.0, 9.0, Fedora 30, 31

Patches

🔴Vulnerability Details

3
OSV
MediaWiki information disclosure2022-05-24
GHSA
MediaWiki information disclosure2022-05-24
OSV
CVE-2019-16738: In MediaWiki through 12019-09-26

📋Vendor Advisories

2
Red Hat
mediawiki: suppressed username information disclosure via Special:Redirect2019-09-25
Debian
CVE-2019-16738: mediawiki - In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of s...2019

💬Community

2
Bugzilla
CVE-2019-16738 mediawiki: suppressed username information disclosure via Special:Redirect [fedora-all]2019-09-26
Bugzilla
CVE-2019-16738 mediawiki: suppressed username information disclosure via Special:Redirect2019-09-26
CVE-2019-16738 — Missing Authorization in Mediawiki | cvebase