CVE-2021-41800: Medium severity MediaWiki vulnerability
MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mediawikito a version that resolves this vulnerability.Fixed in 1:1.31.16-1+deb10u2Fixed in 1:1.31.16-1+deb10u6Fixed in 1:1.35.11-1~deb11u1Fixed in 1:1.35.13-1~deb11u1Fixed in 1:1.39.4-1~deb12u1Fixed in 1:1.39.5-1~deb12u1Fixed in 1:1.39.5-1 - Upgrade
Upgrade
composer/mediawiki/coreto a version that resolves this vulnerability.Fixed in 1.36.2
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41800?
CVE-2021-41800 has a moderate severity level as it allows for denial of service due to lengthy query processing.
How do I fix CVE-2021-41800?
To fix CVE-2021-41800, you should upgrade MediaWiki to version 1.36.2 or later.
What are the affected versions for CVE-2021-41800?
CVE-2021-41800 affects MediaWiki versions prior to 1.36.2.
What specific software is impacted by CVE-2021-41800?
CVE-2021-41800 impacts MediaWiki software including specific Debian and Fedora packages.
Is there a workaround for CVE-2021-41800?
There is no official workaround for CVE-2021-41800, and the only solution is to update to the fixed version.