CVE-2022-41766: Medium severity mediawiki vulnerability
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. Upon an action=rollback operation, the alreadyrolled message can leak a user name (when the user has been revision deleted/suppressed).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-41766?
CVE-2022-41766 is a vulnerability in MediaWiki versions before 1.35.8, 1.36.x before 1.37.5, and 1.38.x before 1.38.3 that allows the leaking of a user's name during a rollback operation.
How severe is CVE-2022-41766?
CVE-2022-41766 has a severity rating of 4.3, which is considered medium.
What is the affected software for CVE-2022-41766?
The affected software for CVE-2022-41766 is MediaWiki versions before 1.35.8, 1.36.x before 1.37.5, and 1.38.x before 1.38.3.
How can I fix CVE-2022-41766?
To fix CVE-2022-41766, users should upgrade to MediaWiki version 1.35.8, 1.37.5, or 1.38.3 depending on the currently used version.
Where can I find more information about CVE-2022-41766?
More information about CVE-2022-41766 can be found at this [link](https://phabricator.wikimedia.org/T307278).