An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page title, and its timestamp, both of which are not supposed to be public information.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5520-1 | mediawiki security update |
EUVD |
EUVD-2023-49656 | An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page title, and its timestamp, both of which are not supposed to be public information. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 19 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-19T18:14:01.953Z
Reserved: 2023-10-09T00:00:00.000Z
Link: CVE-2023-45364
Updated: 2024-08-02T20:21:16.625Z
Status : Modified
Published: 2023-10-09T05:15:09.300
Modified: 2024-11-21T08:26:49.650
Link: CVE-2023-45364
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD