CVE-2020-35480
Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about the hidden status to…
Does this matter?
Lower severity and a low EPSS score (1.54%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about the hidden status to unprivileged viewers. This exists on various code paths.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.54% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- mediawiki/mediawiki · debian/debian linux · fedoraproject/fedora
- Source
- cve@mitre.org
References
- https://lists.debian.org/debian-lts-announce/2020/12/msg00034.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/STT5Z4A3BCXVH3WIPICWU2FP4IPIMUPC/
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-December/000268.htmlMailing List, Release Notes, Vendor Advisory
- https://phabricator.wikimedia.org/T120883Permissions Required
- https://www.debian.org/security/2020/dsa-4816Mailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/12/msg00034.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/STT5Z4A3BCXVH3WIPICWU2FP4IPIMUPC/
- https://lists.wikimedia.org/pipermail/mediawiki-announce/2020-December/000268.htmlMailing List, Release Notes, Vendor Advisory
- https://phabricator.wikimedia.org/T120883Permissions Required
- https://www.debian.org/security/2020/dsa-4816Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.