CVE-2017-0361: api.log contains passwords in plaintext
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0361?
CVE-2017-0361 is classified as a moderate severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2017-0361?
To fix CVE-2017-0361, upgrade MediaWiki to version 1.28.1 or later, or apply the specific patches provided by the maintainers.
What versions of MediaWiki are affected by CVE-2017-0361?
CVE-2017-0361 affects MediaWiki versions prior to 1.28.1, 1.27.2, and 1.23.16.
What type of vulnerability is CVE-2017-0361?
CVE-2017-0361 is an information disclosure vulnerability that may expose passwords in plaintext within the api.log.
Is it possible for attackers to exploit CVE-2017-0361 without access to the system?
While CVE-2017-0361 specifically involves log file access, unintentional exposure of sensitive information can still create risks for an attacker with sufficient access to the logs.