CVE-2019-12473Uncontrolled Resource Consumption in Mediawiki

Severity
7.5HIGHNVD
EPSS
0.5%
top 35.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10
Latest updateMay 24

Description

Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

Packagistmediawiki/core1.27.01.27.6+3
debiandebian/mediawiki< mediawiki 1:1.31.2-1 (bookworm)
NVDmediawiki/mediawiki1.27.01.27.6+3
Debianmediawiki/mediawiki< 1:1.31.2-1+3

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

3
OSV
Wikimedia Potential DOS due to slow WatchedItemStore::countVisitingWatchersMultiple2022-05-24
GHSA
Wikimedia Potential DOS due to slow WatchedItemStore::countVisitingWatchersMultiple2022-05-24
OSV
CVE-2019-12473: Wikimedia MediaWiki 12019-07-10

📋Vendor Advisories

1
Debian
CVE-2019-12473: mediawiki - Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid title...2019
CVE-2019-12473 — Uncontrolled Resource Consumption | cvebase