Impact
MediaWiki’s parser unintentionally processes redirects that point to content in non‑includable namespaces, allowing an attacker to cause the parser to fetch and expose protected data that should be disclosure vulnerability classified as CWE‑200, targeting confidentiality of site content.
Affected Systems
The vulnerability affects all releases of MediaWiki before version 1.46.0 and specifically the releases 1.45.4, 1.44.6 and 1.43.9 from the Wikimedia Foundation.
Risk and Exploitability
The likely attack vector is a crafted request containing a malicious redirect in a namespace. It is inferred that no elevated privileges are required to deliver such a request. The EPSS score of less than 1% indicates a very low probability of exploitation and the vulnerability is not listed in CISA’s KEV catalog, meaning no widespread attacks are known. The CVSS score of 5.7 indicates moderate severity. Nonetheless, because the flaw permits the disclosure of sensitive page content, the confidentiality risk is significant and warrants swift remediation.
OpenCVE Enrichment
Debian DSA