'wikiconfig' API leaked private config variables set through ManageWiki
Package
ManageWiki
(MediaWiki Extension)
Affected versions
Before a1432177e723922be441edc3a6738809e68b9b7b
Patched versions
befb83c66f5b643e174897ea41a8a46679b26304 and after
Impact
The 'wikiconfig' API allows unauthorised retrieval of configuration values of sensitive configuration variables set through ManageWiki.
Patches
https://github.com/miraheze/ManageWiki/compare/99f3b2c8af18...befb83c66f5b.patch
Workarounds
Set
$wgAPIListModules['wikiconfig'] = 'ApiQueryDisabled';
or remove private configuration variables.References
https://phabricator.miraheze.org/T7213
For more information
If you have any questions or comments about this advisory: