CVE-2025-62669: UserInfoCard: activeLocalBlocksAllWikis does not do permissions checks
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure.This issue affects Mediawiki - CentralAuth Extension: from master before 1.39.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62669?
CVE-2025-62669 is classified as a medium severity vulnerability affecting the Wikimedia Foundation Mediawiki - CentralAuth Extension.
How do I fix CVE-2025-62669?
To fix CVE-2025-62669, update the Mediawiki - CentralAuth Extension to version 1.39 or later.
What is the main issue caused by CVE-2025-62669?
CVE-2025-62669 allows exposure of sensitive information to unauthorized actors due to a resource leak.
Which versions of Mediawiki - CentralAuth Extension are affected by CVE-2025-62669?
CVE-2025-62669 affects all versions of the Mediawiki - CentralAuth Extension before version 1.39.
Who is responsible for the vulnerability CVE-2025-62669?
CVE-2025-62669 is a vulnerability attributed to the Wikimedia Foundation's Mediawiki - CentralAuth Extension.