In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.
References
Link | Resource |
---|---|
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7OMG3BMUHGWTAPYTK2NXM6CXF6FYLOUO/ | |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QBAOLXETM5BOYQG6OQVHGB2LNLZUXVN6/ | |
https://phabricator.wikimedia.org/T230402 | Exploit Issue Tracking Patch Third Party Advisory |
https://seclists.org/bugtraq/2019/Oct/32 | Mailing List Third Party Advisory |
https://www.debian.org/security/2019/dsa-4545 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-09-26T01:49:11
Updated: 2019-10-26T19:06:10
Reserved: 2019-09-24T00:00:00
Link: CVE-2019-16738
JSON object: View
NVD Information
Status : Modified
Published: 2019-09-26T02:15:10.833
Modified: 2023-11-07T03:05:42.750
Link: CVE-2019-16738
JSON object: View
Redhat Information
No data.
CWE