First published: Mon Oct 09 2023(Updated: )
An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page title, and its timestamp, both of which are not supposed to be public information.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mediawiki | 1:1.31.16-1+deb10u2 1:1.31.16-1+deb10u7 1:1.35.11-1~deb11u1 1:1.35.13-1~deb11u1 1:1.39.5-1~deb12u1 1:1.39.5-1 | |
MediaWiki MediaWiki | >=1.36.0<1.39.5 | |
MediaWiki MediaWiki | =1.40.0 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-45364 is medium.
CVE-2023-45364 can be exploited by leaking deleted revision existence due to incorrect permissions being checked.
MediaWiki versions 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1 are affected by CVE-2023-45364.
To fix CVE-2023-45364, update to MediaWiki version 1.39.5 or 1.40.1.
You can find more information about CVE-2023-45364 at the following references: [Phabricator](https://phabricator.wikimedia.org/T264765), [Debian Security Advisory](https://www.debian.org/security/2023/dsa-5520), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2023-45364).