CVE-2017-0361: Debian Linux

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Mediawiki Mediawiki: from 1.23.0, up to and including 1.23.16; from 1.27.0, before 1.27.2 (fixed in 1.27.2); from 1.28.0, before 1.28.1 (fixed in 1.28.1)

Published 2018-04-13. Last modified 2026-06-17.