CVE-2021-32722: Uncontrolled Resource Consumption in GlobalNewFiles
GlobalNewFiles is a mediawiki extension. Versions prior to 48be7adb70568e20e961ea1cb70904454a671b1d are affected by an uncontrolled resource consumption vulnerability. A large amount of page moves within a short space of time could overwhelm Database servers due to improper handling of load balancing and a lack of an appropriate index. As a workaround, one may avoid use of the extension unless additional rate limit at the MediaWiki level or via PoolCounter / MySQL is enabled. A patch is available in version 48be7adb70568e20e961ea1cb70904454a671b1d.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32722?
CVE-2021-32722 has been classified as a moderate severity vulnerability due to its potential impact on database servers.
How do I fix CVE-2021-32722?
To fix CVE-2021-32722, you should upgrade to the version of GlobalNewFiles that includes the commit 48be7adb70568e20e961ea1cb70904454a671b1d or later.
What causes CVE-2021-32722?
CVE-2021-32722 is caused by an uncontrolled resource consumption vulnerability that occurs when a large number of page moves are executed in a short period of time.
Which software is affected by CVE-2021-32722?
CVE-2021-32722 affects versions of the GlobalNewFiles mediawiki extension prior to commit 48be7adb70568e20e961ea1cb70904454a671b1d.
What can happen if CVE-2021-32722 is exploited?
If exploited, CVE-2021-32722 can overwhelm database servers, leading to performance degradation or potential downtime.