CVE-2019-12473: High severity mediawiki vulnerability
Potential enwiki DOS due to slow WatchedItemStore::countVisitingWatchersMultiple
Other sources
Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12473?
CVE-2019-12473 is a potential denial-of-service (DoS) vulnerability in certain versions of Wikimedia MediaWiki.
How do I fix CVE-2019-12473?
To fix CVE-2019-12473, upgrade to MediaWiki version 1.32.2, 1.31.2, 1.30.2, or 1.27.6.
Which versions of MediaWiki are affected by CVE-2019-12473?
Affected versions include MediaWiki 1.27.0 through 1.32.1.
What causes the vulnerability CVE-2019-12473?
CVE-2019-12473 is caused by passing invalid titles to the API, which may query the entire watchlist table.
What is the impact of CVE-2019-12473?
The impact of CVE-2019-12473 is the potential for a denial-of-service attack against the affected MediaWiki installations.