CVE Vulnerabilities

CVE-2023-37300

Published: Jun 30, 2023 | Modified: Nov 27, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in the CheckUserLog API in the CheckUser extension for MediaWiki through 1.39.3. There is incorrect access control for visibility of hidden users.

Affected Software

NameVendorStart VersionEnd Version
MediawikiMediawiki*1.39.3 (including)
MediawikiUbuntubionic*
MediawikiUbuntufocal*
MediawikiUbuntukinetic*
MediawikiUbuntulunar*
MediawikiUbuntumantic*
MediawikiUbuntuoracular*
MediawikiUbuntuplucky*
MediawikiUbuntutrusty*
MediawikiUbuntuxenial*

References