CVE-2019-12474: Infoleak
API responses for unpatrolled or (not) autopatrolled recent changes require privileges but may be cached publicly
Other sources
Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12474?
CVE-2019-12474 is classified as a medium severity vulnerability due to its potential for information leak.
How do I fix CVE-2019-12474?
To fix CVE-2019-12474, upgrade MediaWiki to version 1.32.2 or later.
Which versions of MediaWiki are affected by CVE-2019-12474?
MediaWiki versions 1.23.0 through 1.32.1 are affected by CVE-2019-12474.
What type of vulnerability is CVE-2019-12474?
CVE-2019-12474 is an information leak vulnerability that exposes privileged API responses.
Is there a workaround for CVE-2019-12474?
There is no official workaround for CVE-2019-12474; upgrading to a fixed version is recommended.