An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.
During installation, installed file permissions are set to allow anyone to modify those files.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Mediawiki | Mediawiki | * | 1.35.5 (excluding) | 
| Mediawiki | Mediawiki | 1.36.0 (including) | 1.36.3 (excluding) | 
| Mediawiki | Mediawiki | 1.37.0 (including) | 1.37.1 (excluding) | 
| Mediawiki | Ubuntu | bionic | * | 
| Mediawiki | Ubuntu | esm-apps/bionic | * | 
| Mediawiki | Ubuntu | esm-apps/focal | * | 
| Mediawiki | Ubuntu | focal | * | 
| Mediawiki | Ubuntu | hirsute | * | 
| Mediawiki | Ubuntu | impish | * | 
| Mediawiki | Ubuntu | trusty | * | 
| Mediawiki | Ubuntu | upstream | * |