PT-2023-22165 · Mediawiki+1 · Growthexperiments+1

Kosta Harlan

+1

·

Published

2023-03-31

·

Updated

2024-08-20

·

CVE-2023-29137

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GrowthExperiments extension for MediaWiki versions through 1.39.3
Description An issue in the GrowthExperiments extension for MediaWiki allows the UserImpactHandler to inadvertently return the timezone preference for arbitrary users. This can be used to de-anonymize users.
Recommendations For versions through 1.39.3, consider disabling the UserImpactHandler for GrowthExperiments until a patch is available to prevent the potential de-anonymization of users.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4877
ALT-PU-2024-11168
ALT-PU-2024-1228
BIT-MEDIAWIKI-2023-29137
CVE-2023-29137

Affected Products

Alt Linux
Growthexperiments