CVE-2024-29883: CreateWiki's wiki request suppression ignores the suppression settings set by the suppressor
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Suppression of wiki requests does not work as intended, and always restricts visibility to those with the (createwiki) user right regardless of the settings one sets on a given wiki request. This may expose information to users who are not supposed to be able to access it.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29883?
CVE-2024-29883 is a medium-severity vulnerability affecting the Miraheze CreateWiki extension.
How do I fix CVE-2024-29883?
To fix CVE-2024-29883, ensure that permissions are properly configured and apply any available patches from the official repository.
What types of issues are caused by CVE-2024-29883?
CVE-2024-29883 allows improper suppression of wiki requests, leading to unintended visibility of wiki creation requests.
Which software is affected by CVE-2024-29883?
CVE-2024-29883 specifically affects the Miraheze CreateWiki extension for MediaWiki.
Is user data impacted by CVE-2024-29883?
CVE-2024-29883 may expose wiki request visibility to users without the necessary permissions, potentially compromising user data.