First published: Tue Oct 29 2019(Updated: )
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or their differences were viewable) to unprivileged users, thus disclosing potentially sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki AbuseFilter | <=1.34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18612 is a vulnerability discovered in the AbuseFilter extension through version 1.34 for MediaWiki.
The severity of CVE-2019-18612 is medium, with a CVSS score of 5.3.
CVE-2019-18612 allows unprivileged users to view hidden AbuseFilter filters or their differences, which can lead to the disclosure of sensitive information.
MediaWiki version up to and including 1.34 is affected by CVE-2019-18612.
Yes, a fix has been released for CVE-2019-18612. It is recommended to update to the latest version of the AbuseFilter extension for MediaWiki.