Improper authorization control for web services In mediawiki
Description
Wikimedia MediaWik exposed suppressed log in RevisionDelete page Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 1:1.31.2-1 | ||
debian 12 | 1:1.31.2-1 | ||
packagist | 1.27.6, 1.30.2, 1.31.2, 1.32.2 | ||
debian 11 | 1:1.31.2-1 | ||
debian 13 | 1:1.31.2-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5.