Description
In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.
Remediation
References
Related Vulnerabilities
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-3829)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2203)
Jboss EAP Improper Restriction of XML External Entity Reference Vulnerability (CVE-2017-7503)
Oracle Database Server CVE-2011-0882 Vulnerability (CVE-2011-0882)