PT-2019-5357 · Wikimedia+1 · Mediawiki+1

Lucas Werkmeister

+1

·

Published

2017-08-22

·

Updated

2025-09-29

·

CVE-2019-12474

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions 1.23.0 through 1.32.1
Description The issue is related to an information leak in MediaWiki, where privileged API responses may be cached publicly, potentially revealing whether a recent change has been patrolled. This could allow a remote attacker to gain unauthorized access to protected information.
Recommendations For MediaWiki versions 1.23.0 through 1.32.1, update to version 1.32.2, 1.31.2, 1.30.2, or 1.27.6 to resolve the issue.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2017-2095
ALT-PU-2019-2016
ALT-PU-2019-2054
BDU:2020-02564
CVE-2019-12474
DSA-4460-1
GHSA-2QRR-C2GH-PR35
MGASA-2019-0279

Affected Products

Alt Linux
Mediawiki