PT-2021-19416 · Mediawiki+1 · Abusefilter+2
Steinsplitter
·
Published
2021-04-22
·
Updated
2024-03-06
·
CVE-2021-31546
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MediaWiki versions through 1.35.2
Description
An issue in the AbuseFilter extension for MediaWiki incorrectly logged sensitive suppression deletions. These deletions should not have been visible to users with access to view AbuseFilter log data.
Recommendations
For versions through 1.35.2, update to a version that fixes this issue to prevent sensitive information from being logged and visible to unauthorized users.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Abusefilter
Mediawiki