CVE-2021-35197: High severity mediawiki vulnerability
In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-35197?
CVE-2021-35197 is considered a medium severity vulnerability due to unintended API access that can bypass sitewide blocks.
How do I fix CVE-2021-35197?
To fix CVE-2021-35197, update MediaWiki to versions 1.31.16, 1.35.3, 1.36.1 or later.
What types of systems are affected by CVE-2021-35197?
CVE-2021-35197 affects MediaWiki versions prior to 1.31.15, between 1.32.x and 1.35.3, as well as versions earlier than 1.36.1.
What is the nature of the issue in CVE-2021-35197?
CVE-2021-35197 allows bot accounts to perform actions that should be restricted by sitewide blocks via the MediaWiki Action API.
Which applications require attention due to CVE-2021-35197?
Applications running MediaWiki version 1.31.15 or lower, or between 1.32.x and 1.35.3, or 1.36.x before 1.36.1 should be evaluated for CVE-2021-35197.