Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Amandanp

Pesquisador deWikimedia Communities
#41270de 53,633
6.5CVSS total
Vulnerabilidades · 1
PT-2023-22166
6.5
2023-03-31
Mediawiki · Mediawiki Checkuser Extension · CVE-2023-29139
**Name of the Vulnerable Software and Affected Versions** MediaWiki CheckUser extension versions through 1.39.3 **Description** An issue in the CheckUser extension for MediaWiki can cause denial of service when a user with checkuserlog permissions makes many CheckUserLog API requests in certain configurations, resulting in a RequestTimeoutException or upstream request timeout. **Recommendations** For versions through 1.39.3, consider restricting access to the CheckUserLog API endpoint to minimize the risk of denial of service attacks until a patch is available. As a temporary workaround, limiting the number of CheckUserLog API requests from users with checkuserlog permissions may also help mitigate the issue.