PT-2022-18870 · Mediawiki+1 · Mediawiki+1

Legoktm

·

Published

2022-04-18

·

Updated

2024-03-06

·

CVE-2022-28201

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.35.6 MediaWiki versions 1.36.x prior to 1.36.4 MediaWiki versions 1.37.x prior to 1.37.2
Description An issue was discovered in MediaWiki where users with the editinterface permission can trigger infinite recursion. This occurs because a bare local interwiki is mishandled for the mainpage message.
Recommendations For MediaWiki versions prior to 1.35.6, update to version 1.35.6 or later. For MediaWiki versions 1.36.x prior to 1.36.4, update to version 1.36.4 or later. For MediaWiki versions 1.37.x prior to 1.37.2, update to version 1.37.2 or later. As a temporary workaround, consider restricting the editinterface permission to minimize the risk of exploitation.

Exploit

Fix

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2140
ALT-PU-2022-2428
BIT-MEDIAWIKI-2022-28201
CVE-2022-28201
DLA-3117-1
DSA-5246-1
MGASA-2022-0145

Affected Products

Alt Linux
Mediawiki