CVE-2024-47913

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
04/10/2024
Last modified:
17/06/2025

Description

An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the caller is not authorized to view the log details for the filter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* 1.39.9 (excluding)
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* 1.40.0 (including) 1.41.3 (excluding)
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* 1.42.0 (including) 1.42.2 (excluding)