CVE-2022-28203: High severity mediawiki vulnerability
Published Sep 19, 2022
·Updated
A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. When many files exist, requesting Special:NewFiles with actor as a condition can result in a very long running query.
Affected Software
6 affected componentsFixes available
debian/mediawiki<=1:1.31.16-1+deb10u2
1:1.31.16-1+deb10u61:1.35.11-1~deb11u11:1.35.13-1~deb11u11:1.39.4-1~deb12u11:1.39.5-1~deb12u11:1.39.5-1
MediaWiki MediaWiki<1.35.6
MediaWiki MediaWiki>=1.36.0<1.36.4
MediaWiki MediaWiki>=1.37.0<1.37.2
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Patch Available
Event History
Sep 19, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-28203?
The severity of CVE-2022-28203 is high with a CVSS score of 7.5.
2
What is the impact of CVE-2022-28203?
CVE-2022-28203 can result in a denial-of-service (DoS) attack on MediaWiki instances.
3
How can I fix CVE-2022-28203?
Update to MediaWiki versions 1.35.6, 1.36.4, or 1.37.2 to mitigate the vulnerability.
4
Which software versions are affected by CVE-2022-28203?
MediaWiki versions before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2 are affected by CVE-2022-28203.
5
Where can I find more information about CVE-2022-28203?
You can find more information about CVE-2022-28203 on the following references: [1] [2] [3]