Information Exposure Vulnerability in Mediawiki - GlobalBlocking Extension by Wikimedia Foundation
CVE-2025-23073

3.5LOW

Key Information:

Vendor
CVE Published:
14 January 2025

Summary

The Mediawiki - GlobalBlocking Extension, developed by the Wikimedia Foundation, contains a vulnerability that allows unauthorized actors to retrieve embedded sensitive data. This risk is present in versions prior to 1.39.11, 1.41.3, and 1.42.2, highlighting the need for users to update to secure versions to protect against potential data breaches.

Affected Version(s)

Mediawiki - GlobalBlocking Extension master

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Credit

Dom Walden
.