CVE-2023-45364: Medium severity mediawiki vulnerability
An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page title, and its timestamp, both of which are not supposed to be public information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45364?
The severity of CVE-2023-45364 is medium.
How is CVE-2023-45364 exploited?
CVE-2023-45364 can be exploited by leaking deleted revision existence due to incorrect permissions being checked.
Which versions of MediaWiki are affected by CVE-2023-45364?
MediaWiki versions 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1 are affected by CVE-2023-45364.
How can I fix CVE-2023-45364?
To fix CVE-2023-45364, update to MediaWiki version 1.39.5 or 1.40.1.
Where can I find more information about CVE-2023-45364?
You can find more information about CVE-2023-45364 at the following references: [Phabricator](https://phabricator.wikimedia.org/T264765), [Debian Security Advisory](https://www.debian.org/security/2023/dsa-5520), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2023-45364).