CVE-2025-23073: API list=globalblocks can reveal IP of autoblock if username and IP are included in the bgtargets parameter
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlocking Extension allows Retrieve Embedded Sensitive Data.
This issue briefly impacted the master branch of MediaWiki’s GlobalBlocking Extension.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23073?
CVE-2025-23073 is classified as a moderate severity vulnerability due to its potential for exposing sensitive information.
How does CVE-2025-23073 affect the MediaWiki - GlobalBlocking Extension?
CVE-2025-23073 allows unauthorized actors to retrieve embedded sensitive data within the MediaWiki - GlobalBlocking Extension.
What is the impact of CVE-2025-23073?
The impact of CVE-2025-23073 includes the risk of data leakage from the GlobalBlocking Extension in MediaWiki.
How can I fix CVE-2025-23073?
To fix CVE-2025-23073, it is recommended to update to the latest version of the MediaWiki - GlobalBlocking Extension that addresses this vulnerability.
Who is affected by CVE-2025-23073?
CVE-2025-23073 affects users of the Wikimedia Foundation MediaWiki - GlobalBlocking Extension who have not patched the vulnerability.