CVE-2021-42040: High severity MediaWiki MediaWiki vulnerability
An issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allowed for an infinite loop (and php-fpm hang) within the Loops extension because egLoopsCountLimit is mishandled. This could lead to memory exhaustion.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-42040?
CVE-2021-42040 is a vulnerability discovered in MediaWiki through version 1.36.2, which allows for an infinite loop and potential memory exhaustion.
How severe is CVE-2021-42040?
CVE-2021-42040 has a severity rating of 7.5 out of 10, which is considered high.
What software is affected by CVE-2021-42040?
MediaWiki versions up to and including 1.36.2 are affected by CVE-2021-42040.
How can CVE-2021-42040 be exploited?
CVE-2021-42040 can be exploited by using a parser function related to loop control, which can cause an infinite loop and potential memory exhaustion.
Is there a fix available for CVE-2021-42040?
Yes, a fix for CVE-2021-42040 is available in newer versions of MediaWiki. It is recommended to upgrade to a fixed version.