CVE-2025-6927

Description

A flaw was found in MediaWiki, specifically within the handling of block lists via BlockListPager.Php and ApiQueryBlocks.Php. A remote attacker could exploit this vulnerability with user interaction to achieve low confidentiality impact, potentially disclosing limited information related to block lists.

Statement

The impact of this vulnerability is LOW. Autoblocks originating from global account suppressions in MediaWiki are publicly exposed. This information disclosure affects MediaWiki versions from 1.42.0 before 1.39.13, 1.42.7, 1.43.2, and 1.44.0.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Application Data

Frequently Asked Questions

Want to get errata notifications? Sign up here.