PT-2021-19419 · Mediawiki+1 · Mediawiki+2

Daimona

·

Published

2021-04-22

·

Updated

2024-03-06

·

CVE-2021-31549

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki versions through 1.35.2 AbuseFilter extension for MediaWiki through 1.35.2
Description An issue in the AbuseFilter extension for MediaWiki allows the disclosure of suppressed MediaWiki usernames to unprivileged users through the Special:AbuseFilter/examine form.
Recommendations For MediaWiki versions through 1.35.2, update to a version that contains a fix for this issue. For the AbuseFilter extension, restrict access to the Special:AbuseFilter/examine form until a patch is available.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1991
ALT-PU-2021-2091
BIT-MEDIAWIKI-2021-31549
CVE-2021-31549

Affected Products

Alt Linux
Abusefilter Extension
Mediawiki