CVE-2019-18987: Infoleak
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, thus potentially disclosing private or sensitive information within the filter's definition.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-18987?
CVE-2019-18987 is a vulnerability in the AbuseFilter extension for MediaWiki that allows the exposure of previous versions of a public abuse filter, potentially disclosing private or sensitive information within the filter's definition.
What is the severity of CVE-2019-18987?
The severity of CVE-2019-18987 is medium, with a CVSS score of 5.3.
How does CVE-2019-18987 affect Mediawiki Abusefilter?
CVE-2019-18987 affects Mediawiki AbuseFilter version 1.34 and potentially exposes previous versions of public abuse filters, leading to the disclosure of private or sensitive information.
Is there a fix for CVE-2019-18987?
Yes, upgrading to a version of the AbuseFilter extension beyond 1.34 eliminates the vulnerability.
Where can I find more information about CVE-2019-18987?
You can find more information about CVE-2019-18987 in the references provided: [1] [2] [3].