Impact
The AbuseFilter component contains a defect in the QueryAbuseFilters API that discloses hit counts for private filter rules. Based on the description, it is inferred that the API endpoint is accessible without authentication, meaning any client can request these statistics and view data that should only be available to administrators. This flaw is a classic example of Sensitive Data Exposure (CWE‑200) and can potentially reveal usage patterns or internal monitoring activity.
Affected Systems
All installations of the Wikimedia Foundation AbuseFilter that run a version older than 1.46.0 are affected, including releases 1.45.4, 1.44.6, and 1.43.9. Among those vulnerable systems the QueryAbuseFilters endpoint can return private hit counts.
Risk and Exploitability
The vulnerability receives a CVSS score of 5.3, indicating moderate risk. The EPSS score of less than 1 % suggests a very low chance of exploitation. Based on the description, it is inferred that the attack vector is a direct HTTP request to the QueryAbuseFilters endpoint, and that the API is accessible without authentication, so no special privileges or credentials are required. Attackers can trigger the flaw by issuing a simple HTTP request; the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DSA