PT-2022-22316 · Mediawiki+1 · Mediawiki+1

Lucas Werkmeister

+1

·

Published

2022-06-28

·

Updated

2024-08-20

·

CVE-2022-34750

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MediaWiki versions through 1.38.1
Description An issue in MediaWiki allows the creation of larger lexemes than the capped length of a thousand characters, as this length is not validated. This introduces denial-of-service attack vectors within the Wikibase and WikibaseLexeme extensions, related to "Special:NewLexeme" and "Special:NewProperty".
Recommendations For versions through 1.38.1, consider restricting the creation of new lexemes or validating the lemma length to prevent denial-of-service attacks. As a temporary workaround, restrict access to "Special:NewLexeme" and "Special:NewProperty" to minimize the risk of exploitation.

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3361
ALT-PU-2024-11168
ALT-PU-2024-1228
BIT-MEDIAWIKI-2022-34750
CVE-2022-34750

Affected Products

Alt Linux
Mediawiki