CVE-2019-12215: Medium severity mediawiki matomo vulnerability
DISPUTED A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to discover the full path of Matomo on the disk, because lastError.file is used in plugins/CorePluginsAdmin/templates/safemode.twig. NOTE: the vendor disputes the significance of this issue, stating "avoid reporting path disclosures, as we don't consider them as security vulnerabilities."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12215?
CVE-2019-12215 is considered a low severity vulnerability, primarily due to its limited impact.
How do I fix CVE-2019-12215?
To mitigate CVE-2019-12215, upgrade to Matomo version 3.9.2 or later.
What type of vulnerability is CVE-2019-12215?
CVE-2019-12215 is a full path disclosure vulnerability.
What versions of Matomo are affected by CVE-2019-12215?
CVE-2019-12215 affects Matomo version 3.9.1.
What could an attacker potentially gain from exploiting CVE-2019-12215?
An attacker could potentially gain knowledge of the file path structure of the Matomo installation.