PT-2021-23413 · Mediawiki+1 · Mediawiki+1
Cdanis
+1
·
Published
2021-10-01
·
Updated
2025-10-14
·
CVE-2021-41800
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
MediaWiki versions prior to 1.36.2
Description
The issue allows for a denial of service due to resource consumption caused by lengthy query processing time. Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled.
Recommendations
For MediaWiki versions prior to 1.36.2, update to version 1.36.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Special:Contributions page to minimize the risk of exploitation.
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Mediawiki