An issue was discovered in MediaWiki before 1.35.9, 1.36...
Moderate severity
Unreviewed
Published
Jan 12, 2023
to the GitHub Advisory Database
•
Updated Jul 19, 2023
Description
Published by the National Vulnerability Database
Jan 12, 2023
Published to the GitHub Advisory Database
Jan 12, 2023
Last updated
Jul 19, 2023
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are created with file mode 0644, i.e., world readable to local users. These files include credentials data.
References