First published: Mon Sep 21 2020(Updated: )
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/mediawiki/core | >=1.31.0<1.31.9>=1.34.0<1.34.3 | |
debian/mediawiki | 1:1.31.16-1+deb10u2 1:1.31.16-1+deb10u6 1:1.35.11-1~deb11u1 1:1.35.13-1~deb11u1 1:1.39.4-1~deb12u1 1:1.39.5-1~deb12u1 1:1.39.5-1 | |
composer/mediawiki/core | >=1.32.0<1.34.3 | 1.34.3 |
composer/mediawiki/core | >=1.31.0<1.31.9 | 1.31.9 |
Wikimedia MediaWiki | <1.31.10 | |
Wikimedia MediaWiki | >=1.32.0<1.34.4 | |
Fedoraproject Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25813 is a medium severity vulnerability that allows exposure of hidden users in MediaWiki.
To fix CVE-2020-25813, upgrade to MediaWiki versions 1.31.10, 1.34.4, or later.
CVE-2020-25813 affects MediaWiki versions before 1.31.10 and versions between 1.32.0 and 1.34.3.
CVE-2020-25813 allows unauthorized disclosure of hidden user identities, potentially compromising user privacy.
Yes, CVE-2020-25813 can be exploited remotely by anyone with access to the affected MediaWiki installation.