CVE-2024-29883: CreateWiki's wiki request suppression ignores the suppression settings set by the suppressor

Published Mar 26, 2024
·
Updated

CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Suppression of wiki requests does not work as intended, and always restricts visibility to those with the (createwiki) user right regardless of the settings one sets on a given wiki request. This may expose information to users who are not supposed to be able to access it.

Affected Software

2 affected components
Miraheze CreateWiki
Miraheze CreateWiki<2024-03-26

Event History

Mar 26, 2024
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-29883?

CVE-2024-29883 is a medium-severity vulnerability affecting the Miraheze CreateWiki extension.

2

How do I fix CVE-2024-29883?

To fix CVE-2024-29883, ensure that permissions are properly configured and apply any available patches from the official repository.

3

What types of issues are caused by CVE-2024-29883?

CVE-2024-29883 allows improper suppression of wiki requests, leading to unintended visibility of wiki creation requests.

4

Which software is affected by CVE-2024-29883?

CVE-2024-29883 specifically affects the Miraheze CreateWiki extension for MediaWiki.

5

Is user data impacted by CVE-2024-29883?

CVE-2024-29883 may expose wiki request visibility to users without the necessary permissions, potentially compromising user data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203