SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-35480

Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about the hidden status to…

MEDIUM 5.3EPSS 1.54%

Does this matter?

Lower severity and a low EPSS score (1.54%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about the hidden status to unprivileged viewers. This exists on various code paths.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.54% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-203
Affected
mediawiki/mediawiki · debian/debian linux · fedoraproject/fedora
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.