Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.
| Software | From | Fixed in |
|---|---|---|
| mediawiki / mediawiki | 1.23.0 | 1.23.16.x |
| mediawiki / mediawiki | 1.27.0 | 1.27.2 |
| mediawiki / mediawiki | 1.28.0 | 1.28.1 |
| debian / debian_linux | 7.0 | 7.0.x |