Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://www.debian.org/security/2019/dsa-4460 | third party advisory vendor advisory |
https://seclists.org/bugtraq/2019/Jun/12 | mailing list third party advisory issue tracking |
https://phabricator.wikimedia.org/T222038 | third party advisory |
https://lists.wikimedia.org/pipermail/wikitech-l/2019-June/092152.html | vendor advisory mailing list release notes |