CVE-2025-67476

Description

A flaw was found in MediaWiki. This vulnerability, located in the includes/Import/ImportableOldRevisionImporter.Php file, may allow a remote attacker with low privileges to disclose sensitive information. The flaw occurs during the processing of old revisions, potentially leading to unintended exposure of data.

Statement

This LOW impact vulnerability in MediaWiki allows for the leakage of an importer's IP address through EventStreams during the import process. This affects MediaWiki in Fedora Community Projects, specifically versions before 1.44.3 and 1.45.1.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Files or Directories; Read Memory; Read Application Data

Sensitive data may be exposed to attackers.

Frequently Asked Questions

Want to get errata notifications? Sign up here.