CVE-2021-30153: Medium severity mediawiki vulnerability
An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It shouldn't because they are hidden.) This is related to ApiVisualEditor.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-30153?
CVE-2021-30153 is a vulnerability in the VisualEditor extension in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2.
How does CVE-2021-30153 affect MediaWiki?
CVE-2021-30153 affects MediaWiki versions before 1.31.13, and 1.32.x through 1.35.x before 1.35.2.
What is the severity of CVE-2021-30153?
CVE-2021-30153 has a severity rating of 4.3 (Medium).
How can CVE-2021-30153 be exploited?
CVE-2021-30153 can be exploited by using VisualEditor to edit a MediaWiki user page belonging to a hidden user, which discloses the existence of the user.
How can I fix CVE-2021-30153?
To fix CVE-2021-30153, update MediaWiki to version 1.31.13 or apply patches for versions 1.32.x through 1.35.x before 1.35.2.