CVE-2024-29897

CVSS V2 None CVSS V3 None
Description
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users with (delete) or (suppressrevision) on any wiki in the farm to access suppressed wiki requests by going to the request's entry on Special:RequestWikiQueue on the wiki where they have these rights. The same vulnerability was present briefly on the REST API before being quickly corrected in commit `6bc0685`. To our knowledge, the vulnerable commits of the REST API are not running in production anywhere. This vulnerability is fixed in 23415c17ffb4832667c06abcf1eadadefd4c8937.
Overview
  • CVE ID
  • CVE-2024-29897
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-03-28T13:40:43.231Z
  • Last Modified Date
  • 2024-03-28T13:40:43.231Z
History
Created Old Value New Value Data Type Notes
2024-06-26 02:51:10 Added to TrackCVE