CVE-2021-45038Sensitive Information Exposure in Mediawiki

Severity
5.3MEDIUMNVD
EPSS
0.3%
top 43.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 17
Latest updateDec 18

Description

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.35.5-1 (bookworm)
NVDmediawiki/mediawiki1.36.01.36.3+2
Debianmediawiki/mediawiki< 1:1.35.4-1+deb11u2+3

🔴Vulnerability Details

2
GHSA
GHSA-8rcg-5g7w-gw95: An issue was discovered in MediaWiki before 12021-12-18
OSV
CVE-2021-45038: An issue was discovered in MediaWiki before 12021-12-17

📋Vendor Advisories

2
Red Hat
mediawiki: information disclosure2021-12-16
Debian
CVE-2021-45038: mediawiki - An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1....2021
CVE-2021-45038 — Sensitive Information Exposure | cvebase