Information disclosure in MediaWiki - CVE-2020-35480
Published: December 18, 2020 / Updated: December 21, 2020
Vulnerability identifier: #VU49104
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-35480
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the way application handles missing and hidden user accounts. A remote attacker can expose sensitive information about the hidden status to unprivileged viewers.
Affected software
MediaWiki
Arch Linux
Fedora
mediawiki (Debian package)
mediawiki
Arch Linux
Fedora
mediawiki (Debian package)
mediawiki
How to mitigate CVE-2020-35480
Install updates from vendor's website.
MediaWiki - addressed in versions 1.31.11, 1.35.1
mediawiki (Debian package) - update to 1.31.12-1~deb10u1
mediawiki - update to 1.35.1-1.fc33
mediawiki (Debian package) - update to 1.31.12-1~deb10u1
mediawiki - update to 1.35.1-1.fc33