CVE Vulnerabilities

CVE-2019-12474

Published: Jul 10, 2019 | Modified: Aug 24, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki 1.23.0 (including) 1.27.6 (excluding)
Mediawiki Mediawiki 1.30.0 (including) 1.30.2 (excluding)
Mediawiki Mediawiki 1.31.0 (including) 1.31.2 (excluding)
Mediawiki Mediawiki 1.32.0 (including) 1.32.2 (excluding)
Mediawiki Ubuntu bionic *
Mediawiki Ubuntu cosmic *
Mediawiki Ubuntu devel *
Mediawiki Ubuntu disco *
Mediawiki Ubuntu eoan *
Mediawiki Ubuntu esm-apps/bionic *
Mediawiki Ubuntu focal *
Mediawiki Ubuntu groovy *
Mediawiki Ubuntu hirsute *
Mediawiki Ubuntu impish *
Mediawiki Ubuntu jammy *
Mediawiki Ubuntu kinetic *
Mediawiki Ubuntu lunar *
Mediawiki Ubuntu mantic *
Mediawiki Ubuntu noble *
Mediawiki Ubuntu oracular *
Mediawiki Ubuntu trusty *
Mediawiki Ubuntu upstream *

References