CVE-2023-29137
31.03.2023, 19:15
An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. The UserImpactHandler for GrowthExperiments inadvertently returns the timezone preference for arbitrary users, which can be used to de-anonymize users.Enginsight
Vendor | Product | Version |
---|---|---|
mediawiki | mediawiki | 𝑥 ≤ 1.39.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration