|
MediaWiki contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an API operation is requested from 'api.php' via URL or POST parameters, causing the response to contain 'public' cache control headers, which will disclose data to a remote attacker using the same caching HTTP proxy or a local attacker.
|