CVE-2023-29134: Input Validation
Published Mar 27, 2024
·Updated
An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. There is mishandling of backticks to smartSplit.
Affected Software
1 affected component
MediaWiki Cargo<1.39.3
Event History
Mar 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-29134?
CVE-2023-29134 is classified as a medium severity vulnerability due to the mishandling of backticks in the Cargo extension.
2
What version of MediaWiki Cargo is affected by CVE-2023-29134?
CVE-2023-29134 affects MediaWiki Cargo versions up to 1.39.3.
3
How do I fix CVE-2023-29134?
To fix CVE-2023-29134, update the MediaWiki Cargo extension to a version later than 1.39.3.
4
What kind of issues does CVE-2023-29134 cause?
CVE-2023-29134 causes issues related to the mishandling of backticks which can lead to unexpected behavior in the Cargo extension.
5
Is there an available patch for CVE-2023-29134?
Yes, a patch for CVE-2023-29134 has been developed and is included in the latest versions of the Cargo extension.