First published: Tue Jan 10 2023(Updated: )
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. SpecialMobileHistory allows remote attackers to cause a denial of service because database queries are slow.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki MediaWiki | <1.35.9 | |
MediaWiki MediaWiki | >=1.36.0<1.38.5 | |
MediaWiki MediaWiki | =1.39.0 | |
MediaWiki MediaWiki | =1.39.0-rc0 | |
MediaWiki MediaWiki | =1.39.0-rc1 | |
Fedoraproject Fedora | =37 | |
<1.35.9 | ||
>=1.36.0<1.38.5 | ||
=1.39.0 | ||
=1.39.0-rc0 | ||
=1.39.0-rc1 | ||
=37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-22909 is medium with a severity value of 5.3.
CVE-2023-22909 affects MediaWiki versions before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1.
SpecialMobileHistory is a feature in MediaWiki that is vulnerable to CVE-2023-22909.
CVE-2023-22909 can be exploited by remote attackers to cause a denial of service because database queries are slow.
Yes, patches or fixes for CVE-2023-22909 are available in MediaWiki versions 1.35.9, 1.38.5, and 1.39.1.