CVE-2021-41799: High severity MediaWiki vulnerability
MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&list=backlinks) can cause a full table scan.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mediawikito a version that resolves this vulnerability.Fixed in 1:1.31.16-1+deb10u2Fixed in 1:1.31.16-1+deb10u6Fixed in 1:1.35.11-1~deb11u1Fixed in 1:1.35.13-1~deb11u1Fixed in 1:1.39.4-1~deb12u1Fixed in 1:1.39.5-1~deb12u1Fixed in 1:1.39.5-1
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41799?
CVE-2021-41799 has a denial of service impact due to excessive resource consumption from lengthy query processing.
How do I fix CVE-2021-41799?
To fix CVE-2021-41799, update your MediaWiki installation to version 1.36.2 or later.
What versions of MediaWiki are affected by CVE-2021-41799?
CVE-2021-41799 affects MediaWiki versions below 1.36.2.
What is the main exploitation vector for CVE-2021-41799?
The main exploitation vector for CVE-2021-41799 is through the ApiQueryBacklinks function, which can lead to a full table scan.
Is CVE-2021-41799 specific to any operating system?
CVE-2021-41799 affects multiple operating systems, including Debian and Fedora versions up to specific releases.