Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5jq2-gw2c-fg5h

Опубликовано: 20 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension can expose information on the performer of edits and logged actions. This information should not allow public viewing: it is supposed to be viewable only by users with checkuser access.

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension can expose information on the performer of edits and logged actions. This information should not allow public viewing: it is supposed to be viewable only by users with checkuser access.

EPSS

Процентиль: 38%
0.00169
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-668

Связанные уязвимости

CVSS3: 3.5
redhat
около 3 лет назад

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension can expose information on the performer of edits and logged actions. This information should not allow public viewing: it is supposed to be viewable only by users with suppression rights.

CVSS3: 5.3
nvd
около 3 лет назад

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension can expose information on the performer of edits and logged actions. This information should not allow public viewing: it is supposed to be viewable only by users with suppression rights.

EPSS

Процентиль: 38%
0.00169
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-668