CVE-2024-47848

Oct. 5, 2024, 12:15 a.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Mediawiki - PageTriage

  • 1.39.X before 1.39.9
  • 1.41.X before 1.41.3
  • 1.42.X before 1.42.2

Source

c4f26cc8-17ff-4c99-b5e2-38fc1793eacc

Tags

CVE-2024-47848 details

Published : Oct. 5, 2024, 12:15 a.m.
Last Modified : Oct. 5, 2024, 12:15 a.m.

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - PageTriage allows Authentication Bypass.This issue affects Mediawiki - PageTriage: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

References

URL Source
https://gerrit.wikimedia.org/r/q/I0288a715f7040a14ab7f70b2888fe1ef77a44588 c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
https://phabricator.wikimedia.org/T366991 c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
https://phabricator.wikimedia.org/T368628 c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
This website uses the NVD API, but is not approved or certified by it.