PT-2024-28933 · Mediawiki+1 · Mediawiki Checkuser Extension+1

Dreamy_Jazz

·

Published

2024-07-06

·

Updated

2025-06-19

·

CVE-2024-40597

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaWiki CheckUser extension versions through 1.42.1
Description An issue was discovered in the CheckUser extension for MediaWiki. It can expose suppressed information for log events, as the log deleted attribute is not respected.
Recommendations For versions through 1.42.1, consider updating to a version where this issue is fixed, as the current version can expose sensitive information. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2025-5905
BIT-MEDIAWIKI-2024-40597
CVE-2024-40597

Affected Products

Alt Linux
Mediawiki Checkuser Extension