PT-2021-19424 · Mediawiki+1 · Mediawiki+2
Martin Urbanec
+1
·
Published
2021-04-22
·
Updated
2024-03-06
·
CVE-2021-31553
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
MediaWiki versions through 1.35.2
Description
An issue in the CheckUser extension allows MediaWiki usernames with trailing whitespace to be stored in the cu log database table, causing denial of service for certain CheckUser extension pages and functionality. This could interfere with usage tracking, for example, by turning off Special:CheckUserLog.
Recommendations
For versions through 1.35.2, consider temporarily restricting access to the CheckUser extension until a fix is applied to prevent the storage of usernames with trailing whitespace in the cu log database table.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Checkuser Extension
Mediawiki