PT-2021-21122 · Mediawiki+1 · Mediawiki+1

St47

·

Published

2021-06-12

·

Updated

2024-03-06

·

CVE-2021-36125

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: MediaWiki versions through 1.36
Description: An issue was discovered in the CentralAuth extension. The Special:GlobalRenameRequest page is vulnerable to infinite loops and denial of service attacks when a user's current username is beyond an arbitrary maximum configuration value (MaxNameChars).
Recommendations: For MediaWiki versions through 1.36, consider restricting the MaxNameChars configuration value to prevent usernames from exceeding the maximum allowed length, thereby mitigating the risk of infinite loops and denial of service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Infinite Loop

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1991
ALT-PU-2021-2091
BIT-MEDIAWIKI-2021-36125
CVE-2021-36125

Affected Products

Alt Linux
Mediawiki