CVE-2023-22909: Medium severity mediawiki vulnerability
Published Jan 10, 2023
·Updated
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. SpecialMobileHistory allows remote attackers to cause a denial of service because database queries are slow.
Affected Software
6 affected components
MediaWiki<1.35.9
MediaWiki>=1.36.0<1.38.5
MediaWiki=1.39.0
MediaWiki=1.39.0-rc0
MediaWiki=1.39.0-rc1
fedoraproject fedora=37
Remediation
Patch Available
Event History
Jan 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-22909?
The severity of CVE-2023-22909 is medium with a severity value of 5.3.
2
How does CVE-2023-22909 affect MediaWiki?
CVE-2023-22909 affects MediaWiki versions before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1.
3
What is SpecialMobileHistory?
SpecialMobileHistory is a feature in MediaWiki that is vulnerable to CVE-2023-22909.
4
How can CVE-2023-22909 be exploited?
CVE-2023-22909 can be exploited by remote attackers to cause a denial of service because database queries are slow.
5
Are there any patches or fixes for CVE-2023-22909?
Yes, patches or fixes for CVE-2023-22909 are available in MediaWiki versions 1.35.9, 1.38.5, and 1.39.1.