An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mediawiki | Mediawiki | * | 1.35.12 (excluding) |
Mediawiki | Mediawiki | 1.36.0 (including) | 1.39.5 (excluding) |
Mediawiki | Mediawiki | 1.40.0 (including) | 1.40.0 (including) |
Mediawiki | Ubuntu | bionic | * |
Mediawiki | Ubuntu | lunar | * |
Mediawiki | Ubuntu | mantic | * |
Mediawiki | Ubuntu | trusty | * |
Mediawiki | Ubuntu | xenial | * |