Page MenuHomeMiraheze

Private wiki search results (page titles) can be incorrectly cached
Closed, ResolvedPublic

Description

We're deploying a fix but this was caught by our automated security task alerts.

Event Timeline

On 12 November, 2021, Site Reliability Engineering was made aware that search results on private wikis may have accidentally been cached and thus publicly visible. SRE took steps immediately to remediate the issue and confirmed only search results were publicly visible. There is currently no indication anyone purposefully viewed private wiki search results through means of the cached version available. If you have any questions, please feel free to email sre{{@}}miraheze.org or ask on #miraheze-sre on IRC/Discord. ~~~~~

This is a draft announcement, please let me know what you think about it.

Unknown Object (User) moved this task from Backlog to Bugs on the MediaWiki board.Nov 13 2021, 16:56
Unknown Object (User) moved this task from Backlog to Short Term on the MediaWiki (SRE) board.
RhinosF1 claimed this task.

Closing, will post Agent's announcement in a bit.

RhinosF1 changed the visibility from "Custom Policy" to "Public (No Login Required)".Nov 14 2021, 08:44
RhinosF1 changed the edit policy from "Custom Policy" to "All Users".