CVE Vulnerabilities

CVE-2023-37300

Published: Jun 30, 2023 | Modified: Jul 06, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorrect access control for visibility of hidden users.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki * 1.39.3 (including)
Mediawiki Ubuntu bionic *
Mediawiki Ubuntu kinetic *
Mediawiki Ubuntu lunar *
Mediawiki Ubuntu mantic *
Mediawiki Ubuntu trusty *
Mediawiki Ubuntu xenial *

References