Description
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are created with file mode 0644, i.e., world readable to local users. These files include credentials data.
Remediation
References
Related Vulnerabilities
WordPress Plugin AdSanity Arbitrary File Upload (1.8.1)
Oracle Database Server Cryptographic Issues Vulnerability (CVE-2006-0270)
WordPress Plugin Import and export users and customers Cross-Site Request Forgery (1.14.1.3)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6625)