Vulnerability Description
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or their differences were viewable) to unprivileged users, thus disclosing potentially sensitive information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mediawiki | Abusefilter | <= 1.34 |
Related Weaknesses (CWE)
References
- https://gerrit.wikimedia.org/r/q/Ie23e8234ae550273bf3f6f9c5ac45b7fc54eec2aPatchVendor Advisory
- https://phabricator.wikimedia.org/T104807PatchVendor Advisory
- https://gerrit.wikimedia.org/r/q/Ie23e8234ae550273bf3f6f9c5ac45b7fc54eec2aPatchVendor Advisory
- https://phabricator.wikimedia.org/T104807PatchVendor Advisory
FAQ
What is CVE-2019-18612?
CVE-2019-18612 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or their differences were viewable) to unprivileged u...
How severe is CVE-2019-18612?
CVE-2019-18612 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-18612?
Check the references section above for vendor advisories and patch information. Affected products include: Mediawiki Abusefilter.