Security Advisory

CVE-2024-29897

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-03-28 13:40:43
Last updated 2024-09-03 18:09:56
Assigner GitHub_M
State PUBLISHED

Description

CreateWiki is Mirahezes MediaWiki extension for requesting & creating wikis. It is possible for users with (delete) or (suppressrevision) on any wiki in the farm to access suppressed wiki requests by going to the requests entry on Special:RequestWikiQueue on the wiki where they have these rights. The same vulnerability was present briefly on the REST API before being quickly corrected in commit `6bc0685`. To our knowledge, the vulnerable commits of the REST API are not running in production anywhere. This vulnerability is fixed in 23415c17ffb4832667c06abcf1eadadefd4c8937.