Description
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3671-1 | mediawiki security update |
Debian DSA |
DSA-5520-1 | mediawiki security update |
EUVD |
EUVD-2023-2825 | An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set. |
Github GHSA |
GHSA-w5fx-cx7f-6vr9 | MediaWiki Denial of Service vulnerability |
References
History
Tue, 15 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-15T18:00:10.847Z
Reserved: 2023-10-09T00:00:00.000Z
Link: CVE-2023-45363
Updated: 2024-08-02T20:21:16.463Z
Status : Modified
Published: 2023-10-09T05:15:09.220
Modified: 2024-11-21T08:26:49.407
Link: CVE-2023-45363
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA