First published: Mon May 29 2023(Updated: )
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. Upon an action=rollback operation, the alreadyrolled message can leak a user name (when the user has been revision deleted/suppressed).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MediaWiki | <1.35.8 | |
MediaWiki MediaWiki | >=1.36.0<1.37.5 | |
MediaWiki MediaWiki | >=1.38.0<1.38.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41766 is a vulnerability in MediaWiki versions before 1.35.8, 1.36.x before 1.37.5, and 1.38.x before 1.38.3 that allows the leaking of a user's name during a rollback operation.
CVE-2022-41766 has a severity rating of 4.3, which is considered medium.
The affected software for CVE-2022-41766 is MediaWiki versions before 1.35.8, 1.36.x before 1.37.5, and 1.38.x before 1.38.3.
To fix CVE-2022-41766, users should upgrade to MediaWiki version 1.35.8, 1.37.5, or 1.38.3 depending on the currently used version.
More information about CVE-2022-41766 can be found at this [link](https://phabricator.wikimedia.org/T307278).