CVE-2023-45364: Debian Linux

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page title, and its timestamp, both of which are not supposed to be public information.

Affected products

  • Debian Debian Linux: version 11.0 only; version 12.0 only
  • Mediawiki Mediawiki: from 1.36.0, before 1.39.5 (fixed in 1.39.5); version 1.40.0 only

Published 2023-10-09. Last modified 2026-06-17.