CVE Vulnerabilities

CVE-2021-36125

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jul 02, 2021 | Modified: Jul 07, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops and denial of service attacks when a users current username is beyond an arbitrary maximum configuration value (MaxNameChars).

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki * 1.36 (including)

References