{"id":"CVE-2022-41766","details":"An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. Upon an action=rollback operation, the alreadyrolled message can leak a user name (when the user has been revision deleted/suppressed).","aliases":["BIT-mediawiki-2022-41766"],"modified":"2026-04-10T04:51:29.138473Z","published":"2023-05-29T21:15:09.757Z","references":[{"type":"FIX","url":"https://phabricator.wikimedia.org/T307278"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wikimedia/mediawiki","events":[{"introduced":"0"},{"fixed":"19c5cf34a22f599467644f206f537aa78f50efd4"},{"introduced":"bc542ec6d8573dfb906b468901799e0017875f1e"},{"fixed":"370d89fff96c8c378651d93cb0bb183d4ff76e3e"},{"introduced":"09fc2a4ea5c1d57779dea6526f0d4487cd950217"},{"fixed":"d063f3bcce7b9694074218cb09d3c693b45bb003"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"1.35.8"},{"introduced":"1.36.0"},{"fixed":"1.37.5"},{"introduced":"1.38.0"},{"fixed":"1.38.3"}]}}],"versions":["1.1.0","1.3.0beta1","1.35.0","1.35.0-rc.0","1.35.0-rc.1","1.35.0-rc.2","1.35.0-rc.3","1.35.1","1.35.2","1.35.3","1.35.4","1.35.5","1.35.6","1.35.7","1.37.0","1.37.0-rc.0","1.37.0-rc.1","1.37.0-rc.2","1.37.1","1.37.2","1.37.3","1.37.4","1.38.0","1.38.1","1.38.2","1.5.0alpha1","1.5.0alpha2","1.5.0beta1","1.5.0beta2","1.5.0beta3","1.5.0beta4","1.6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41766.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}