CVE-2021-30153
4.3
MEDIUM
CVSS 3.1
EPSS 0.22%
Description
An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It shouldn't because they are hidden.) This is related to ApiVisualEditor.
How to fix CVE-2021-30153
To remediate CVE-2021-30153, upgrade the affected package to a fixed version below.
- —upgrade to 1.31.13 or later
- —upgrade to 1:1.35.2-1 or later
Is CVE-2021-30153 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.31.13, >= 1.32.0, < 1.35.2
- from 0, < 1:1.35.2-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |