An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applied to entries.)
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://phabricator.wikimedia.org/T326867 | issue tracking |