CVE-2021-46148: Infoleak
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Some unprivileged users can view confidential information (e.g., IP addresses and User-Agent headers for election traffic) on a testwiki SecurePoll instance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-46148?
CVE-2021-46148 has been classified with a high severity level due to the exposure of confidential information.
How do I fix CVE-2021-46148?
To fix CVE-2021-46148, upgrade MediaWiki to version 1.35.5, 1.36.3, or 1.37.1 or later.
What information can be exposed due to CVE-2021-46148?
CVE-2021-46148 allows unprivileged users to view confidential information such as IP addresses and User-Agent headers for election traffic.
Which versions of MediaWiki are affected by CVE-2021-46148?
CVE-2021-46148 affects MediaWiki versions prior to 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1.
Who is affected by CVE-2021-46148?
CVE-2021-46148 affects installations of MediaWiki configured for SecurePoll where unprivileged users have access.