CVE-2021-41801: High severity MediaWiki MediaWiki vulnerability
The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mediawikito a version that resolves this vulnerability.Fixed in 1:1.31.16-1+deb10u2Fixed in 1:1.31.16-1+deb10u6Fixed in 1:1.35.11-1~deb11u1Fixed in 1:1.35.13-1~deb11u1Fixed in 1:1.39.4-1~deb12u1Fixed in 1:1.39.5-1~deb12u1Fixed in 1:1.39.5-1
Event History
Frequently Asked Questions
What is CVE-2021-41801?
CVE-2021-41801 is a vulnerability in the ReplaceText extension through 1.41 for MediaWiki that has Incorrect Access Control.
What is the severity of CVE-2021-41801?
The severity of CVE-2021-41801 is high, with a CVSS score of 8.8.
How does CVE-2021-41801 impact MediaWiki?
CVE-2021-41801 allows a blocked user to still run a replace job in MediaWiki, even if they are blocked.
What is the affected software for CVE-2021-41801?
The affected software for CVE-2021-41801 includes MediaWiki versions 1.31.16, 1.35.0 to 1.35.4, and 1.36.0 to 1.36.2.
How do I fix CVE-2021-41801 in MediaWiki?
To fix CVE-2021-41801 in MediaWiki, update to versions 1.31.16-1+deb10u2, 1.31.16-1+deb10u6, 1.35.11-1~deb11u1, 1.35.13-1~deb11u1, 1.39.4-1~deb12u1, 1.39.5-1~deb12u1, or 1.39.5-1.