Mediawiki · Mediawiki · CVE-2023-45364
**Name of the Vulnerable Software and Affected Versions**
MediaWiki versions 1.36.x through 1.39.x before 1.39.5
MediaWiki versions 1.40.x before 1.40.1
**Description**
An issue was discovered in includes/page/Article.php. Deleted revision existence is leaked due to incorrect permissions being checked, revealing a given revision ID belonged to the given page title and its timestamp, which are not supposed to be public information.
**Recommendations**
For MediaWiki versions 1.36.x through 1.39.x before 1.39.5, update to version 1.39.5 or later.
For MediaWiki versions 1.40.x before 1.40.1, update to version 1.40.1 or later.