Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.
{
"versions": [
{
"introduced": "1.23.0"
},
{
"last_affected": "1.23.16"
},
{
"introduced": "1.27.0"
},
{
"fixed": "1.27.2"
},
{
"introduced": "1.28.0"
},
{
"fixed": "1.28.1"
}
]
}