VulnerabilityModified
CVE-2021-31546
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2.
MEDIUM 4.3EPSS 0.72%
Does this matter?
Lower severity and a low EPSS score (0.72%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly logged sensitive suppression deletions, which should not have been visible to users with access to view AbuseFilter log data.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.72% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- mediawiki/mediawiki
- Source
- cve@mitre.org
References
- https://gerrit.wikimedia.org/r/q/I38a0a24fa32ca7a052b6940864a32b3856e84553Issue Tracking, Third Party Advisory
- https://phabricator.wikimedia.org/T71617Third Party Advisory
- https://gerrit.wikimedia.org/r/q/I38a0a24fa32ca7a052b6940864a32b3856e84553Issue Tracking, Third Party Advisory
- https://phabricator.wikimedia.org/T71617Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.