Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://lists.wikimedia.org/pipermail/wikitech-l/2018-September/090849.html | mailing list patch vendor advisory |
http://www.securitytracker.com/id/1041695 | vdb entry third party advisory |
https://phabricator.wikimedia.org/T199029 | third party advisory patch |