CVE-2023-45364Incorrect Permission Assignment in Mediawiki

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 69.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 9

Description

An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page title, and its timestamp, both of which are not supposed to be public information.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

debiandebian/mediawiki< mediawiki 1:1.39.5-1~deb12u1 (bookworm)
NVDmediawiki/mediawiki1.36.01.39.5+1
Debianmediawiki/mediawiki< 1:1.39.5-1~deb12u1+2

Also affects: Debian Linux 11.0, 12.0

🔴Vulnerability Details

2
OSV
CVE-2023-45364: An issue was discovered in includes/page/Article2023-10-09
GHSA
GHSA-mjh3-fcq9-8g4h: An issue was discovered in includes/page/Article2023-10-09

📋Vendor Advisories

1
Debian
CVE-2023-45364: mediawiki - An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through...2023
CVE-2023-45364 — Incorrect Permission Assignment | cvebase