Description
An issue was discovered in DifferenceEngine.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. diff-multi-sameuser (aka "X intermediate revisions by the same user not shown") ignores username suppression. This is an information leak.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3671-1 | mediawiki security update |
Debian DSA |
DSA-5520-1 | mediawiki security update |
EUVD |
EUVD-2023-49655 | An issue was discovered in DifferenceEngine.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. diff-multi-sameuser (aka "X intermediate revisions by the same user not shown") ignores username suppression. This is an information leak. |
References
History
Tue, 04 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-04T17:12:46.030Z
Reserved: 2023-10-09T00:00:00.000Z
Link: CVE-2023-45362
No data.
Status : Modified
Published: 2023-11-03T05:15:30.773
Modified: 2025-11-04T18:15:41.890
Link: CVE-2023-45362
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD