An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information for log events. (The log_deleted attribute is not respected.)
References
Link | Resource |
---|---|
https://phabricator.wikimedia.org/T326865 |
Configurations
No configuration.
History
No history.
Information
Published : 2024-07-07 00:15
Updated : 2024-07-08 15:49
NVD link : CVE-2024-40597
Mitre link : CVE-2024-40597
CVE.ORG link : CVE-2024-40597
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor