PT-2021-18245 · Miraheze · Managewiki

Universal-Omega

·

Published

2021-04-28

·

Updated

2021-05-08

·

CVE-2021-29483

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions: ManageWiki (affected versions not specified)
Description: The issue concerns the ManageWiki extension to the MediaWiki project, where the 'wikiconfig' API endpoint leaked private configuration variables set through the ManageWiki variable to all users.
Recommendations: For all affected versions, consider setting $wgAPIListModules['wikiconfig'] = 'ApiQueryDisabled'; or remove private config as a workaround until a patch is applied. Apply the patch available at https://github.com/miraheze/ManageWiki/compare/99f3b2c8af18...befb83c66f5b.patch to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29483
GHSA-JMC9-RV2F-G8VV

Affected Products

Managewiki