CVE-2024-29898
CVSS V2 None
CVSS V3 None
Description
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. An oversight during the writing of the patch for CVE-2024-29897 may have exposed suppressed wiki requests to private wikis that added Special:RequestWikiQueue to the read whitelist to users without the `(read)` permission. This vulnerability is fixed in 8f8442ed5299510ea3e58416004b9334134c149c.
Overview
- CVE ID
- CVE-2024-29898
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-03-28T13:43:07.988Z
- Last Modified Date
- 2024-06-04T17:56:54.259Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/miraheze/CreateWiki/security/advisories/GHSA-5rcv-cf88-gv8v | x_refsource_CONFIRM |
https://github.com/miraheze/CreateWiki/security/advisories/GHSA-4rcf-3cj2-46mq | x_refsource_MISC |
https://github.com/miraheze/CreateWiki/commit/8f8442ed5299510ea3e58416004b9334134c149c | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-29898 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-29898 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 02:37:49 | Added to TrackCVE |