CVE-2015-8002: Medium severity mediawiki vulnerability
The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 allows remote authenticated users to cause a denial of service (disk consumption) via a file upload using one byte chunks.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8002?
CVE-2015-8002 has a severity rating that indicates the potential for denial of service attacks due to disk consumption.
How do I fix CVE-2015-8002?
To mitigate CVE-2015-8002, upgrade MediaWiki to versions 1.23.11, 1.24.4, or 1.25.3 or later.
Who is affected by CVE-2015-8002?
CVE-2015-8002 affects remote authenticated users uploading files in vulnerable versions of MediaWiki.
What type of vulnerability is CVE-2015-8002?
CVE-2015-8002 is a denial of service vulnerability caused by the chunked upload API in MediaWiki.
What versions of MediaWiki are affected by CVE-2015-8002?
MediaWiki versions prior to 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 are affected by CVE-2015-8002.