First published: Mon Oct 09 2023(Updated: )
An issue was discovered in the PageTriage extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. Usernames of hidden users are exposed.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MediaWiki | <1.35.12 | |
MediaWiki MediaWiki | >=1.36.0<1.39.5 | |
MediaWiki MediaWiki | =1.40.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-45369.
CVE-2023-45369 has a severity level of medium (4.3).
The versions of MediaWiki affected by CVE-2023-45369 are 1.35.12, 1.36.x through 1.39.x, and 1.40.x before 1.40.1.
The description of CVE-2023-45369 is that usernames of hidden users are exposed.
Yes, you can find references for CVE-2023-45369 at the following URLs: [https://gerrit.wikimedia.org/r/c/mediawiki/extensions/PageTriage/+/960676](https://gerrit.wikimedia.org/r/c/mediawiki/extensions/PageTriage/+/960676) and [https://phabricator.wikimedia.org/T344359](https://phabricator.wikimedia.org/T344359).