{"id":"BIT-mediawiki-2020-12051","details":"The CentralAuth extension through REL1_34 for MediaWiki allows remote attackers to obtain sensitive hidden account information via an api.php?action=query&meta=globaluserinfo&guiuser= request. In other words, the information can be retrieved via the action API even though access would be denied when simply visiting wiki/Special:CentralAuth in a web browser.","aliases":["CVE-2020-12051"],"modified":"2024-01-31T15:40:39.817Z","published":"2024-01-31T15:31:26.902Z","database_specific":{"cpes":["cpe:2.3:a:mediawiki:mediawiki:-:*:*:*:*:*:*:*"],"severity":"High"},"references":[{"type":"WEB","url":"https://gerrit.wikimedia.org/r/#/q/I3c80641dc1202df7428714f0ca44717a51ff6021"},{"type":"WEB","url":"https://phabricator.wikimedia.org/T250594"}],"affected":[{"package":{"name":"mediawiki","ecosystem":"Bitnami","purl":"pkg:bitnami/mediawiki"},"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/mediawiki/BIT-mediawiki-2020-12051.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}],"schema_version":"1.7.3"}