Vulnerability CVE-2020-35480: Information

Description

An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about the hidden status to unprivileged viewers. This exists on various code paths.

Severity: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Published: Dec. 18, 2020
Modified: Nov. 7, 2023
Error type identifier: CWE-203

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
mediawikisisyphus1.35.1-alt11.40.1-alt2ALT-PU-2020-3554-1263831Fixed
mediawikip101.35.1-alt11.40.1-alt2ALT-PU-2020-3554-1263831Fixed
mediawikip91.35.1-alt11.36.1-alt1ALT-PU-2020-3568-1263837Fixed
mediawikic10f11.35.1-alt11.37.2-alt1ALT-PU-2020-3554-1263831Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*
      End excliding
      1.35.1

      Configuration 2

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*