CVE-2021-31547

An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. Its AbuseFilterCheckMatch API reveals suppressed edits and usernames to unprivileged users through the iteration of crafted AbuseFilter rules.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:05

Type Values Removed Values Added
References () https://gerrit.wikimedia.org/r/q/I3f7dbd8b873d411e37c8c3aac2339bf5ec36907d - Issue Tracking, Third Party Advisory () https://gerrit.wikimedia.org/r/q/I3f7dbd8b873d411e37c8c3aac2339bf5ec36907d - Issue Tracking, Third Party Advisory
References () https://gerrit.wikimedia.org/r/q/I4900b1be73323599d74e3164447f81eded094d75 - Issue Tracking, Third Party Advisory () https://gerrit.wikimedia.org/r/q/I4900b1be73323599d74e3164447f81eded094d75 - Issue Tracking, Third Party Advisory
References () https://phabricator.wikimedia.org/T223654 - Third Party Advisory () https://phabricator.wikimedia.org/T223654 - Third Party Advisory

Information

Published : 2021-04-22 03:15

Updated : 2024-11-21 06:05


NVD link : CVE-2021-31547

Mitre link : CVE-2021-31547

CVE.ORG link : CVE-2021-31547


JSON object : View

Products Affected

mediawiki

  • mediawiki
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor