VulnerabilityModified
CVE-2024-40598
The API can expose suppressed information for log events.
MEDIUM 4.3EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applied to entries.)
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- mediawiki/mediawiki
- Source
- cve@mitre.org
References
- https://phabricator.wikimedia.org/T326867Issue Tracking
- https://phabricator.wikimedia.org/T326867Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.