Suppressed Wiki Requests May Have Been Exposed to Private Wikis Due to Oversight
CVE-2024-29898

4.9MEDIUM

Key Information:

Vendor

Miraheze

Vendor
CVE Published:
28 March 2024

What is CVE-2024-29898?

CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. An oversight during the writing of the patch for CVE-2024-29897 may have exposed suppressed wiki requests to private wikis that added Special:RequestWikiQueue to the read whitelist to users without the (read) permission. This vulnerability is fixed in 8f8442ed5299510ea3e58416004b9334134c149c.

Affected Version(s)

CreateWiki 23415c17ffb4832667c06abcf1eadadefd4c8937

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.