HIGH7.5
GHSA-w5fx-cx7f-6vr9
MediaWiki Denial of Service vulnerability
Quick fix
GHSA-w5fx-cx7f-6vr9 — mediawiki/core: upgrade to the fixed version with the command below.
composer require mediawiki/core:^1.35.12Details
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/mediawiki/core
Introduced in:
0Fixed in: 1.35.12Fix
composer require mediawiki/core:^1.35.12Packagist/mediawiki/core
Introduced in:
1.36.0Fixed in: 1.39.5Fix
composer require mediawiki/core:^1.39.5Packagist/mediawiki/core
Introduced in:
1.40.0Fixed in: 1.40.1Fix
composer require mediawiki/core:^1.40.1References
- https://nvd.nist.gov/vuln/detail/CVE-2023-45363[ADVISORY]
- https://github.com/wikimedia/mediawiki/commit/24c3ef2474c6daa20ed48168d46196a55346dfd8[WEB]
- https://github.com/wikimedia/mediawiki[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2023/11/msg00027.html[WEB]
- https://phabricator.wikimedia.org/T333050[WEB]
- https://www.debian.org/security/2023/dsa-5520[WEB]