First published: Mon Oct 09 2023(Updated: )
An issue was discovered in the CheckUser extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. A user can use a rest.php/checkuser/v0/useragent-clienthints/revision/ URL to store an arbitrary number of rows in cu_useragent_clienthints, leading to a denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaWiki | <1.35.12 | |
MediaWiki | >=1.36.0<1.39.5 | |
MediaWiki | =1.40.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-45367.
The severity of CVE-2023-45367 is medium.
MediaWiki versions before 1.35.12, 1.36.x through 1.39.5, and 1.40.x before 1.40.1 are affected by CVE-2023-45367.
CVE-2023-45367 allows a user to store an arbitrary number of rows, leading to a denial of service and potential data corruption.
Yes, upgrading to MediaWiki versions 1.35.12, 1.39.5, or 1.40.1 will resolve the vulnerability.