CVE-2022-41766
NixOS vulnerability analysis and mitigation

Overview

CVE-2022-41766 is a security vulnerability discovered in MediaWiki versions before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. The vulnerability allows information disclosure where upon an action=rollback operation, the alreadyrolled message can leak a user name that has been revision deleted/suppressed (NVD, Phabricator).

Technical details

The vulnerability exists in MediaWiki's rollback functionality. When performing a rollback action through action=rollback, if a user has been revision deleted or suppressed, the system would still display their username in the 'alreadyrolled' message, effectively leaking sensitive information that should have been hidden. The issue has been assigned a CVSS v3.1 base score of 4.3 (MEDIUM) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N (NVD).

Impact

The vulnerability leads to information disclosure, specifically exposing usernames that have been intentionally hidden through revision deletion or suppression. This could compromise user privacy and potentially reveal sensitive information that was meant to be redacted from the system (Phabricator).

Mitigation and workarounds

The vulnerability has been patched in MediaWiki versions 1.35.8, 1.37.5, and 1.38.3. The fix involves hiding suppressed users from the rollback page error messages. Users are advised to upgrade to these or later versions to mitigate the vulnerability (Phabricator).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management