CVE-2025-6927
Description
A flaw was found in MediaWiki, specifically within the handling of block lists via BlockListPager.Php and ApiQueryBlocks.Php. A remote attacker could exploit this vulnerability with user interaction to achieve low confidentiality impact, potentially disclosing limited information related to block lists.
Statement
The impact of this vulnerability is LOW. Autoblocks originating from global account suppressions in MediaWiki are publicly exposed. This information disclosure affects MediaWiki versions from 1.42.0 before 1.39.13, 1.42.7, 1.43.2, and 1.44.0.
Mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Understanding the Weakness (CWE)
Confidentiality
Technical Impact: Read Application Data
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.