First published: Sat Jul 06 2024(Updated: )
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can expose suppressed information for log events. (TimelineService does not support properly suppressing.)
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki | <=1.42.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40596 is considered a medium severity vulnerability due to its ability to expose suppressed log event information.
To fix CVE-2024-40596, upgrade the MediaWiki CheckUser extension to a version later than 1.42.1.
MediaWiki versions up to and including 1.42.1 are affected by CVE-2024-40596.
The Special:Investigate feature is compromised in CVE-2024-40596, potentially exposing suppressed information.
The vulnerability in CVE-2024-40596 is caused by TimelineService's improper handling of suppressed log event information.