First published: Mon Oct 11 2021(Updated: )
MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&list=backlinks) can cause a full table scan.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mediawiki | 1:1.31.16-1+deb10u2 1:1.31.16-1+deb10u6 1:1.35.11-1~deb11u1 1:1.35.13-1~deb11u1 1:1.39.4-1~deb12u1 1:1.39.5-1~deb12u1 1:1.39.5-1 | |
MediaWiki | <1.36.2 | |
Fedora | =33 | |
Fedora | =34 | |
Fedora | =35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41799 has a denial of service impact due to excessive resource consumption from lengthy query processing.
To fix CVE-2021-41799, update your MediaWiki installation to version 1.36.2 or later.
CVE-2021-41799 affects MediaWiki versions below 1.36.2.
The main exploitation vector for CVE-2021-41799 is through the ApiQueryBacklinks function, which can lead to a full table scan.
CVE-2021-41799 affects multiple operating systems, including Debian and Fedora versions up to specific releases.