Mediawiki · Createwiki · CVE-2024-29898
**Name of the Vulnerable Software and Affected Versions**
CreateWiki versions prior to the version containing the fix in commit 8f8442ed5299510ea3e58416004b9334134c149c
**Description**
An issue in CreateWiki, a MediaWiki extension, may have exposed suppressed wiki requests to private wikis. This occurred when Special:RequestWikiQueue was added to the read whitelist, potentially allowing users without the `read` permission to access it.
**Recommendations**
For versions prior to the fix, update to a version that includes the fix in commit 8f8442ed5299510ea3e58416004b9334134c149c to resolve the issue. As a temporary workaround, consider removing Special:RequestWikiQueue from the read whitelist for private wikis until the update is applied.