An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applied to entries.)
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://phabricator.wikimedia.org/T326867 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published: 2024-07-06T00:00:00.000Z
Updated: 2025-03-25T16:10:43.828Z
Reserved: 2024-07-06T00:00:00.000Z
Link: CVE-2024-40598
Updated: 2024-08-02T04:33:11.911Z
Status : Modified
Published: 2024-07-07T00:15:10.240
Modified: 2025-03-25T17:15:59.000
Link: CVE-2024-40598
No data.
ReportizFlow