VYPR
Medium severity5.3NVD Advisory· Published Oct 9, 2023· Updated Jun 17, 2026

CVE-2023-45364

CVE-2023-45364

Description

An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page title, and its timestamp, both of which are not supposed to be public information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*range: >=1.36.0,<1.39.5
    • cpe:2.3:a:mediawiki:mediawiki:1.40.0:-:*:*:*:*:*:*
    • (no CPE)range: <1.39.5, <1.40.1
    • (no CPE)
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*
  • osv-coords
    Range: >= 1.36.0, < 1.39.5

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.