CVE-2021-36126: Critical severity mediawiki vulnerability
An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36. If the MediaWiki:Abusefilter-blocker message is invalid within the content language, the filter user falls back to the English version, but that English version could also be invalid on a wiki. This would result in a fatal error, and potentially fail to block or restrict a potentially nefarious user.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36126?
CVE-2021-36126 has a medium severity rating due to potential issues with content language fallback in MediaWiki.
How do I fix CVE-2021-36126?
To mitigate CVE-2021-36126, ensure the MediaWiki:Abusefilter-blocker message is correctly defined in the content language.
Which versions of MediaWiki are affected by CVE-2021-36126?
CVE-2021-36126 affects MediaWiki versions up to and including 1.36.
What are the potential impacts of CVE-2021-36126?
The primary impact of CVE-2021-36126 is that users may experience incorrect feedback from the AbuseFilter extension due to invalid message fallbacks.
Is there a known exploit for CVE-2021-36126?
As of now, there are no widely reported exploits known for CVE-2021-36126.