CVE-2021-41800Allocation of Resources Without Limits or Throttling in Mediawiki

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 60.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11
Latest updateMay 24

Description

MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

Packagistmediawiki/core< 1.36.2
debiandebian/mediawiki< mediawiki 1:1.35.4-1 (bookworm)
NVDmediawiki/mediawiki< 1.36.2
Debianmediawiki/mediawiki< 1:1.35.4-1~deb11u1+3

Also affects: Fedora 33, 34, 35

Patches

🔴Vulnerability Details

3
OSV
MediaWiki allows a denial of service2022-05-24
GHSA
MediaWiki allows a denial of service2022-05-24
OSV
CVE-2021-41800: MediaWiki before 12021-10-11

📋Vendor Advisories

2
Red Hat
mediawiki: mishandled PoolCounter's protection may result DoS when visiting Special:Contributions.2021-09-30
Debian
CVE-2021-41800: mediawiki - MediaWiki before 1.36.2 allows a denial of service (resource consumption because...2021
CVE-2021-41800 — Mediawiki vulnerability | cvebase