CVE-2021-44854: Medium severity mediawiki vulnerability
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The REST API publicly caches results from private wikis.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44854?
The severity of CVE-2021-44854 is medium with a severity value of 5.3.
How does CVE-2021-44854 impact MediaWiki?
CVE-2021-44854 allows the REST API to publicly cache results from private wikis, potentially exposing sensitive information.
Which versions of MediaWiki are affected by CVE-2021-44854?
MediaWiki versions before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1 are affected by CVE-2021-44854.
What is the remedy for CVE-2021-44854 in Debian's MediaWiki package?
For Debian's MediaWiki package, the remedy for CVE-2021-44854 is to update to version 1:1.39.5-1~deb12u1 or later.
Where can I find more information about CVE-2021-44854?
More information about CVE-2021-44854 can be found at the following links: [phabricator.wikimedia.org](https://phabricator.wikimedia.org/T292763), [lists.wikimedia.org](https://lists.wikimedia.org/hyperkitty/list/wikitech-l@lists.wikimedia.org/thread/QEN3EK4JXAVJMJ5GF3GYOAKNJPEKFQYA/), and [security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2021-44854).