Description
An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page title, and its timestamp, both of which are not supposed to be public information.
Remediation
References
Related Vulnerabilities
WordPress Plugin Timeline Calendar SQL Injection (1.2)
WordPress 4.0.x Cross-Domain Flash Injection Vulnerability (4.0 - 4.0.21)
WordPress Plugin IgnitionDeck Security Bypass (1.1.6)
Magento CVE-2019-8091 Vulnerability (CVE-2019-8091)
WordPress Plugin Backup and Staging by WP Time Capsule Security Bypass (1.21.15)