PT-2024-3257 · Mediawiki+2 · Mediawiki+2

Dreamy_Jazz

·

Published

2024-02-16

·

Updated

2025-06-19

·

CVE-2024-34506

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MediaWiki versions prior to 1.39.7 MediaWiki versions 1.40.x prior to 1.40.3 MediaWiki versions 1.41.x prior to 1.41.1
Description An issue in the includes/specials/SpecialMovePage.php file of MediaWiki can lead to a denial of service. If a user with the necessary rights to move a page opens Special:MovePage for a page with tens of thousands of subpages, the page will exceed the maximum request time, resulting in a denial of service.
Recommendations For MediaWiki versions prior to 1.39.7, update to version 1.39.7 or later. For MediaWiki versions 1.40.x prior to 1.40.3, update to version 1.40.3 or later. For MediaWiki versions 1.41.x prior to 1.41.1, update to version 1.41.1 or later. As a temporary workaround, consider restricting access to the Special:MovePage page for users with the necessary rights to move pages, especially for pages with a large number of subpages.

Fix

DoS

Resource Exhaustion

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-5905
BDU:2024-03488
BIT-MEDIAWIKI-2024-34506
CVE-2024-34506
DLA-3796-1
DSA-5651-1

Affected Products

Alt Linux
Mediawiki
Red Os