An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly logged sensitive suppression deletions, which should not have been visible to users with access to view AbuseFilter log data.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://phabricator.wikimedia.org/T71617 | third party advisory |
https://gerrit.wikimedia.org/r/q/I38a0a24fa32ca7a052b6940864a32b3856e84553 | issue tracking third party advisory |