#VU31009 Information disclosure in MediaWiki - CVE-2019-12474
Published: July 10, 2019 / Updated: July 17, 2020
MediaWiki
MediaWiki.org
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.