PT-2021-23412 · Mediawiki+1 · Mediawiki+1

Published

2021-10-01

·

Updated

2024-03-06

·

CVE-2021-41799

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.36.2
Description The issue allows for a denial of service due to resource consumption caused by lengthy query processing time. This can be triggered through the ApiQueryBacklinks endpoint, specifically with the action=query&list=backlinks query, which can cause a full table scan.
Recommendations For versions prior to 1.36.2, update to version 1.36.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the ApiQueryBacklinks endpoint or limiting the use of the action=query&list=backlinks query to minimize the risk of exploitation.

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3561
ALT-PU-2022-1199
BIT-MEDIAWIKI-2021-41799
CVE-2021-41799
DLA-2779-1
DSA-4979-1
MGASA-2021-0477

Affected Products

Alt Linux
Mediawiki