CVE-2021-31546

An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly logged sensitive suppression deletions, which should not have been visible to users with access to view AbuseFilter log data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:05

Type Values Removed Values Added
References () https://gerrit.wikimedia.org/r/q/I38a0a24fa32ca7a052b6940864a32b3856e84553 - Issue Tracking, Third Party Advisory () https://gerrit.wikimedia.org/r/q/I38a0a24fa32ca7a052b6940864a32b3856e84553 - Issue Tracking, Third Party Advisory
References () https://phabricator.wikimedia.org/T71617 - Third Party Advisory () https://phabricator.wikimedia.org/T71617 - Third Party Advisory

Information

Published : 2021-04-22 03:15

Updated : 2024-11-21 06:05


NVD link : CVE-2021-31546

Mitre link : CVE-2021-31546

CVE.ORG link : CVE-2021-31546


JSON object : View

Products Affected

mediawiki

  • mediawiki
CWE
CWE-532

Insertion of Sensitive Information into Log File