CVE-2022-41766Incorrect Permission Assignment in Mediawiki

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 79.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 29

Description

An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. Upon an action=rollback operation, the alreadyrolled message can leak a user name (when the user has been revision deleted/suppressed).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDmediawiki/mediawiki1.36.01.37.5+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-75q9-6ghf-f447: An issue was discovered in MediaWiki before 12023-05-29
OSV
CVE-2022-41766: An issue was discovered in MediaWiki before 12023-05-29

📋Vendor Advisories

1
Debian
CVE-2022-41766: mediawiki - An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.3...2022
CVE-2022-41766 — Incorrect Permission Assignment | cvebase