CVE-2024-40598: Medium severity mediawiki vulnerability
Published Jul 6, 2024
·Updated
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The logdeleted attribute is not applied to entries.)
Affected Software
1 affected component
MediaWiki MediaWiki<=1.42.1
Event History
Jul 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jul 7, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40598?
CVE-2024-40598 is considered a moderate severity vulnerability due to the exposure of suppressed log event information.
2
How can I fix CVE-2024-40598?
To fix CVE-2024-40598, upgrade to the MediaWiki version 1.42.2 or later.
3
Which versions of MediaWiki are affected by CVE-2024-40598?
CVE-2024-40598 affects MediaWiki versions up to and including 1.42.1.
4
What type of information is exposed by CVE-2024-40598?
CVE-2024-40598 exposes suppressed information related to log events that should not be available.
5
Is the CheckUser extension vulnerable in all MediaWiki versions?
The CheckUser extension is only vulnerable in MediaWiki versions up to 1.42.1.