Private configs are exposed by DataDump
Package
MirahezeMagic
(MediaWiki Extension)
Affected versions
With ManageWiki above a1432177e723922be441edc3a6738809e68b9b7b
Patched versions
dd8efe5644495886388842ac75ae5e0b5b3f3f56 and after
Impact
DataDumps prior to the above commit incorrectly allowed anyone to view private config. These variables no longer are included.
Patches
https://github.com/miraheze/MirahezeMagic/compare/400bc5709922067a175a5ed9d8f0e177d85e02a7...dd8efe5644495886388842ac75ae5e0b5b3f3f56.patch
Workarounds
Don't set private config or disable the ManageWiki backup functionality.
References
https://phabricator.miraheze.org/T7216
For more information
If you have any questions or comments about this advisory: