Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-35480
HistoryDec 18, 2020 - 12:00 a.m.

CVE-2020-35480

2020-12-1800:00:00
ubuntu.com
ubuntu.com
14
mediawiki
1.35.1
security
issue
unix
cve-2020-35480
sensitive information

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.002

Percentile

59.9%

An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts
that don’t exist) and hidden users (accounts that have been explicitly
hidden due to being abusive, or similar) that the viewer cannot see are
handled differently, exposing sensitive information about the hidden status
to unprivileged viewers. This exists on various code paths.

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.002

Percentile

59.9%