Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-45364: ⚓ T264765 Users without permission are shown MediaWiki:Missing-revision-permission

An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page title, and its timestamp, both of which are not supposed to be public information.

CVE
#php#auth

Risk Rating

Low

Author Affiliation

Wikimedia Communities

  • Task Graph
  • Mentions
  • Duplicates

Event Timeline

Restricted Application added a subscriber: Aklapper.

Reedy renamed this task from Users without permission are shown Wikimedia:Missing-revision-permission/de to Users without permission are shown MediaWiki:Missing-revision-permission/de.

Reedy renamed this task from Users without permission are shown MediaWiki:Missing-revision-permission/de to Users without permission are shown MediaWiki:Missing-revision-permission.

Reedy added a parent task: Restricted Task.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907