Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-67476

Опубликовано: 03 фев. 2026
Источник: redhat
CVSS3: 4.3

Описание

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/ImportableOldRevisionImporter.Php. This issue affects MediaWiki: from * before 1.44.3, 1.45.1.

A flaw was found in MediaWiki. This vulnerability, located in the includes/Import/ImportableOldRevisionImporter.Php file, may allow a remote attacker with low privileges to disclose sensitive information. The flaw occurs during the processing of old revisions, potentially leading to unintended exposure of data.

Отчет

This LOW impact vulnerability in MediaWiki allows for the leakage of an importer's IP address through EventStreams during the import process. This affects MediaWiki in Fedora Community Projects, specifically versions before 1.44.3 and 1.45.1.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Low
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2436186MediaWiki: MediaWiki: Information disclosure vulnerability in ImportableOldRevisionImporter.Php

4.3 Medium

CVSS3

Связанные уязвимости

ubuntu
2 месяца назад

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/ImportableOldRevisionImporter.Php. This issue affects MediaWiki: from * before 1.44.3, 1.45.1.

nvd
2 месяца назад

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/ImportableOldRevisionImporter.Php. This issue affects MediaWiki: from * before 1.44.3, 1.45.1.

debian
2 месяца назад

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is ...

github
2 месяца назад

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/ImportableOldRevisionImporter.Php. This issue affects MediaWiki: from * before 1.44.3, 1.45.1.

4.3 Medium

CVSS3