First published: Mon Sep 19 2022(Updated: )
A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. When many files exist, requesting Special:NewFiles with actor as a condition can result in a very long running query.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mediawiki | <=1:1.31.16-1+deb10u2 | 1:1.31.16-1+deb10u6 1:1.35.11-1~deb11u1 1:1.35.13-1~deb11u1 1:1.39.4-1~deb12u1 1:1.39.5-1~deb12u1 1:1.39.5-1 |
Wikimedia MediaWiki | <1.35.6 | |
Wikimedia MediaWiki | >=1.36.0<1.36.4 | |
Wikimedia MediaWiki | >=1.37.0<1.37.2 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-28203 is high with a CVSS score of 7.5.
CVE-2022-28203 can result in a denial-of-service (DoS) attack on MediaWiki instances.
Update to MediaWiki versions 1.35.6, 1.36.4, or 1.37.2 to mitigate the vulnerability.
MediaWiki versions before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2 are affected by CVE-2022-28203.
You can find more information about CVE-2022-28203 on the following references: [1] [2] [3]