Medium severity4.3NVD Advisory· Published Mar 31, 2023· Updated Jun 17, 2026
CVE-2023-29137
CVE-2023-29137
Description
An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. The UserImpactHandler for GrowthExperiments inadvertently returns the timezone preference for arbitrary users, which can be used to de-anonymize users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: <=1.39.3
Patches
Vulnerability mechanics
References
1- phabricator.wikimedia.org/T328643nvdIssue TrackingPatch
News mentions
0No linked articles in our index yet.