CVE-2021-36128: Critical severity mediawiki vulnerability
Published Jul 2, 2021
·Updated
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppression blocks are not properly implemented.
Affected Software
1 affected component
MediaWiki MediaWiki<=1.36
Remediation
Patch Available
Event History
Jul 2, 2021
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-36128?
CVE-2021-36128 is classified as a moderate severity vulnerability as it affects the CentralAuth extension in MediaWiki.
2
How do I fix CVE-2021-36128?
To fix CVE-2021-36128, users should upgrade their MediaWiki installation to version 1.37 or later.
3
What software versions are affected by CVE-2021-36128?
CVE-2021-36128 affects MediaWiki versions up to and including 1.36.
4
What type of vulnerability is CVE-2021-36128?
CVE-2021-36128 is a vulnerability related to improper implementation of autoblocks for CentralAuth-issued suppression blocks.
5
Who is impacted by CVE-2021-36128?
Users and administrators of MediaWiki installations that use the CentralAuth extension up to version 1.36 are impacted by CVE-2021-36128.