CVE-2021-44858: High severity mediawiki vulnerability
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44858?
CVE-2021-44858 has a medium severity rating due to its potential impact on the privacy of private wiki pages.
How do I fix CVE-2021-44858?
To fix CVE-2021-44858, upgrade MediaWiki to version 1.35.5, 1.36.3, or 1.37.1 or later.
What versions of MediaWiki are affected by CVE-2021-44858?
CVE-2021-44858 affects MediaWiki versions prior to 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1.
What type of attack does CVE-2021-44858 enable?
CVE-2021-44858 allows an attacker to view private pages on a private wiki by exploiting a specific sequence of actions.
What environments are impacted by CVE-2021-44858?
CVE-2021-44858 primarily impacts private wikis using MediaWiki that have at least one page set in $wgWhitelistRead.