CVE Vulnerabilities

CVE-2018-0504

Insertion of Sensitive Information into Log File

Published: Oct 04, 2018 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
4.4 LOW
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
MediawikiMediawiki1.31.0 (including)1.31.1 (excluding)
MediawikiMediawiki1.27.5 (including)1.27.5 (including)
MediawikiMediawiki1.29.3 (including)1.29.3 (including)
MediawikiMediawiki1.30.1 (including)1.30.1 (including)
Red Hat OpenShift Container Platform 3.10RedHatmediawiki-0:1.27.7-1.el7*
Red Hat OpenShift Container Platform 3.9RedHatmediawiki123-0:1.23.17-1.el7*
MediawikiUbuntubionic*
MediawikiUbuntuesm-apps/bionic*
MediawikiUbuntutrusty*
MediawikiUbuntuupstream*

Potential Mitigations

References