icon

We found results for “

CVE-2024-47913

Good to know:

icon

Date: October 3, 2024

An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the caller is not authorized to view the log details for the filter.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Exposure of Sensitive Information to an Unauthorized Actor

CWE-200

Insertion of Sensitive Information into Log File

CWE-532

Top Fix

icon

Upgrade Version

Upgrade to version mediawiki/abuse-filter - dev-wmf/1.38.0-wmf.22;mediawiki/abuse-filter - dev-wmf/1.36.0-wmf.1;mediawiki/abuse-filter - dev-wmf/1.37.0-wmf.23;mediawiki/abuse-filter - dev-wmf/1.39.0-wmf.2;mediawiki/abuse-filter - dev-REL1_21;mediawiki/abuse-filter - dev-wmf/1.38.0-wmf.15;mediawiki/abuse-filter - dev-wmf/1.38.0-wmf.18;mediawiki/abuse-filter - dev-wmf/1.38.0-wmf.6;mediawiki/abuse-filter - dev-wmf/1.37.0-wmf.19;mediawiki/abuse-filter - dev-REL1_43;mediawiki/abuse-filter - dev-wmf/1.37.0-wmf.20;mediawiki/abuse-filter - dev-wmf/1.38.0-wmf.4;mediawiki/abuse-filter - dev-wmf/1.43.0-wmf.25;mediawiki/abuse-filter - dev-wmf/1.37.0-wmf.14;mediawiki/abuse-filter - dev-wmf/1.44.0-wmf.1;mediawiki/abuse-filter - dev-wmf/1.36.0-wmf.4;mediawiki/abuse-filter - dev-REL1_38;mediawiki/abuse-filter - dev-wmf/1.36.0-wmf.3;mediawiki/abuse-filter - dev-wmf/1.40.0-wmf.10;mediawiki/abuse-filter - dev-wmf/1.39.0-wmf.3

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us