HTMLUserTextField exposes existence of hidden users (CVE-2022-41765). reassignEdits doesn't update results in an IP range check on Special:Contributions (CVE-2022-41767) . MGASA-2022-0370 - Updated mediawiki packages fix security vulnerability Publication date: 13 Oct 2022 URL: https://advisories.mageia.org/MGASA-2022-0370.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-41765, CVE-2022-41767 HTMLUserTextField exposes existence of hidden users (CVE-2022-41765). reassignEdits doesn't update results in an IP range check on Special:Contributions (CVE-2022-41767) References: - https://bugs.mageia.org/show_bug.cgi?id=30943 - https://lists.wikimedia.org/hyperkitty/list/
Get the latest Linux and open source security news straight to your inbox.