CVE-2023-36674: Input Validation
An issue was discovered in MediaWiki before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1. It is possible to bypass the Bad image list (aka badFile) by using the thumb parameter (aka Manualthumb) of the File syntax.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-36674?
CVE-2023-36674 is a vulnerability in MediaWiki versions before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1 that allows bypassing the Bad image list through the use of the thumb parameter in the File syntax.
How severe is CVE-2023-36674?
CVE-2023-36674 has a severity rating of 5.3 (medium).
How does CVE-2023-36674 affect MediaWiki?
CVE-2023-36674 affects MediaWiki versions before 1.35.11, 1.36.x through 1.38.x before 1.38.7, 1.39.x before 1.39.4, and 1.40.x before 1.40.1.
How can I fix CVE-2023-36674 in MediaWiki?
To fix CVE-2023-36674, you should update MediaWiki to version 1.35.11, 1.38.7, 1.39.4, or 1.40.1 depending on the branch you are using.
Where can I find more information about CVE-2023-36674?
You can find more information about CVE-2023-36674 in the references provided: [Phabricator](https://phabricator.wikimedia.org/T335612), [Gerrit](https://gerrit.wikimedia.org/r/c/mediawiki/core/+/934571/), and [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2023-36674).