cve/2024/CVE-2024-29898.md
2024-05-25 21:48:12 +02:00

18 lines
968 B
Markdown

### [CVE-2024-29898](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-29898)
![](https://img.shields.io/static/v1?label=Product&message=CreateWiki&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%2023415c17ffb4832667c06abcf1eadadefd4c8937%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-200%3A%20Exposure%20of%20Sensitive%20Information%20to%20an%20Unauthorized%20Actor&color=brighgreen)
### Description
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. An oversight during the writing of the patch for CVE-2024-29897 may have exposed suppressed wiki requests to private wikis that added Special:RequestWikiQueue to the read whitelist to users without the `(read)` permission. This vulnerability is fixed in 8f8442ed5299510ea3e58416004b9334134c149c.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds