Inappropriate coding practices In mediawiki/core
Description
MediaWiki Denial of Service vulnerability An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 1.35.12, 1.39.5, 1.40.1 | ||
debian 11 | 1:1.35.13-1~deb11u1 | ||
debian 12 | 1:1.39.5-1~deb12u1 | ||
debian 13 | 1:1.39.5-1 | ||
debian 14 | 1:1.39.5-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3.