CVE-2021-44856: Medium severity mediawiki vulnerability
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A title blocked by AbuseFilter can be created via Special:ChangeContentModel due to the mishandling of the EditFilterMergedContent hook return value.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44856?
The severity of CVE-2021-44856 is medium with a CVSS score of 5.3.
How can I exploit CVE-2021-44856?
We do not provide information on how to exploit vulnerabilities.
How do I check if my version of MediaWiki is affected by CVE-2021-44856?
You can check if your version of MediaWiki is affected by CVE-2021-44856 by referring to the affected software list in the vulnerability description.
How do I fix CVE-2021-44856?
To fix CVE-2021-44856, update your MediaWiki installation to version 1.35.5, 1.36.3, or 1.37.1.
Where can I find more information about CVE-2021-44856?
You can find more information about CVE-2021-44856 in the references provided: [Phabricator](https://phabricator.wikimedia.org/T271037), [Wikitech-l Mailing List](https://lists.wikimedia.org/hyperkitty/list/wikitech-l@lists.wikimedia.org/thread/QEN3EK4JXAVJMJ5GF3GYOAKNJPEKFQYA/), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2021-44856).