First published: Fri Jan 20 2023(Updated: )
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension can expose information on the performer of edits and logged actions. This information should not allow public viewing: it is supposed to be viewable only by users with suppression rights.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MediaWiki | =1.39.0 | |
MediaWiki MediaWiki | =1.39.0-rc0 | |
MediaWiki MediaWiki | =1.39.0-rc1 | |
MediaWiki MediaWiki | =1.39.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-39193.
CVE-2022-39193 has a severity rating of 5.3 (medium).
The CheckUser extension for MediaWiki versions 1.39.0 to 1.39.1 are affected by CVE-2022-39193.
This vulnerability in the CheckUser extension for MediaWiki can expose information on the performer of edits and logged actions, potentially allowing unauthorized viewing of sensitive data.
Yes, upgrading to a patched version of the CheckUser extension for MediaWiki (1.39.2 or later) will address this vulnerability.