An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are created with file mode 0644, i.e., world readable to local users. These files include credentials data.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-01-12T00:00:00

Updated: 2024-08-03T15:02:36.447Z

Reserved: 2022-12-22T00:00:00

Link: CVE-2022-47927

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-01-12T06:15:08.167

Modified: 2024-11-21T07:32:32.463

Link: CVE-2022-47927

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-01-12T00:00:00Z

Links: CVE-2022-47927 - Bugzilla