Vulnerability Name: | CVE-2020-35480 (CCN-193536) | ||||||||||||
Assigned: | 2020-12-17 | ||||||||||||
Published: | 2020-12-17 | ||||||||||||
Updated: | 2022-04-08 | ||||||||||||
Summary: | An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about the hidden status to unprivileged viewers. This exists on various code paths. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-203 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-35480 Source: XF Type: UNKNOWN mediawiki-cve202035480-info-disc(193536) Source: MLIST Type: Mailing List, Third Party Advisory [debian-lts-announce] 20201223 [SECURITY] [DLA 2504-1] mediawiki security update Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2020-0be2d40e13 Source: CCN Type: MediaWiki Mailing List, Thu Dec 17 23:16:51 UTC 2020 Security and maintenance release: 1.31.11 / 1.35.1 Source: MISC Type: Mailing List, Release Notes, Vendor Advisory https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-December/000268.html Source: MISC Type: Permissions Required https://phabricator.wikimedia.org/T120883 Source: DEBIAN Type: Mailing List, Third Party Advisory DSA-4816 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |