Impact
MediaWiki’s parser unintentionally processes redirects that point to content in non‑includable namespaces, allowing an attacker to cause the parser to fetch and expose protected data that should be hidden from public view. This is a direct disclosure vulnerability classified as CWE‑200, targeting confidentiality of site content.
Affected Systems
The vulnerability affects all releases of MediaWiki before version 1.46.0 and specifically the releases 1.45.4, 1.44.6 and 1.43.9 from the Wikimedia Foundation.
Risk and Exploitability
The likely attack vector is a crafted request containing a malicious redirect in a namespace that is normally excluded from parsing. It is inferred that no elevated privileges are required to deliver such a request. The EPSS score of less than 1% indicates a very low probability of exploitation and the vulnerability is not listed in CISA’s KEV catalog, meaning no widespread attacks are known. Nonetheless, because the flaw permits the disclosure of sensitive page content, the confidentiality risk is significant and warrants swift remediation.
OpenCVE Enrichment
Debian DSA