CVE-2023-45363: High severity mediawiki vulnerability
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45363?
The severity of CVE-2023-45363 is high (CVSS 7.5).
How does CVE-2023-45363 affect MediaWiki?
CVE-2023-45363 affects MediaWiki versions before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1.
What is the impact of CVE-2023-45363?
CVE-2023-45363 allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and conv.
How can I fix CVE-2023-45363?
To fix CVE-2023-45363, upgrade to MediaWiki version 1.35.12, 1.39.5, or 1.40.1 depending on your installed version.
Are there any references related to CVE-2023-45363?
Yes, you can find references related to CVE-2023-45363 at the following links: [link1](https://phabricator.wikimedia.org/T333050), [link2](https://www.debian.org/security/2023/dsa-5520), [link3](https://security-tracker.debian.org/tracker/CVE-2023-45363).