CVE Vulnerabilities

CVE-2019-12473

Published: Jul 10, 2019 | Modified: Aug 24, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki 1.27.0 (including) 1.27.6 (excluding)
Mediawiki Mediawiki 1.30.0 (including) 1.30.2 (excluding)
Mediawiki Mediawiki 1.31.0 (including) 1.31.2 (excluding)
Mediawiki Mediawiki 1.32.0 (including) 1.32.2 (excluding)

References