CVE-2023-45367: Medium severity mediawiki vulnerability
Published Oct 9, 2023
·Updated
An issue was discovered in the CheckUser extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. A user can use a rest.php/checkuser/v0/useragent-clienthints/revision/ URL to store an arbitrary number of rows in cuuseragentclienthints, leading to a denial of service.
Affected Software
3 affected components
MediaWiki MediaWiki<1.35.12
MediaWiki MediaWiki>=1.36.0<1.39.5
MediaWiki MediaWiki=1.40.0
Event History
Oct 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-45367.
2
What is the severity of CVE-2023-45367?
The severity of CVE-2023-45367 is medium.
3
Which software versions are affected by CVE-2023-45367?
MediaWiki versions before 1.35.12, 1.36.x through 1.39.5, and 1.40.x before 1.40.1 are affected by CVE-2023-45367.
4
What is the impact of CVE-2023-45367?
CVE-2023-45367 allows a user to store an arbitrary number of rows, leading to a denial of service and potential data corruption.
5
Is there a fix available for CVE-2023-45367?
Yes, upgrading to MediaWiki versions 1.35.12, 1.39.5, or 1.40.1 will resolve the vulnerability.