PT-2022-24796 · Unknown+2 · Growthexperiments+2

Urbanecm_Wmf

·

Published

2022-09-02

·

Updated

2024-08-20

·

CVE-2022-39194

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MediaWiki versions 1.38.2 and earlier
Description An issue was discovered in the community configuration pages for the GrowthExperiments extension, which could cause a site to become unavailable due to insufficient validation when certain actions, including page moves, were performed.
Recommendations For MediaWiki versions 1.38.2 and earlier, consider disabling the GrowthExperiments extension until a patch is available. Restrict access to the community configuration pages to minimize the risk of exploitation. Avoid performing certain actions, such as page moves, on these pages until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3361
ALT-PU-2024-11168
ALT-PU-2024-1228
BIT-MEDIAWIKI-2022-39194
CVE-2022-39194

Affected Products

Alt Linux
Growthexperiments
Mediawiki