CVE-2021-31553
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in the CheckUser extension for MediaWiki through 1.35.2. MediaWiki usernames with trailing whitespace could be stored in the cu_log database table such that denial of service occurred for certain CheckUser extension pages and functionality. For example, the attacker could turn off Special:CheckUserLog and thus interfere with usage tracking.
Se detectó un problema en la extensión CheckUser para MediaWiki versiones hasta 1.35.2. Unos nombres de usuario de MediaWiki con espacios en blanco al final podrían ser almacenados en la tabla de la base de datos cu_log de manera que se produjera una denegación de servicio para determinadas páginas de extensión y funcionalidad CheckUser. Por ejemplo, el atacante podría desactivar Special: CheckUserLog y así interferir con el seguimiento del uso
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-04-22 CVE Reserved
- 2021-04-22 CVE Published
- 2024-01-05 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-428: Unquoted Search Path or Element
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/CheckUser/+/666963 | Issue Tracking | |
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/CheckUser/+/666964 | Issue Tracking | |
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/CheckUser/+/667023 | Issue Tracking | |
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/CheckUser/+/667024 | Issue Tracking | |
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/CheckUser/+/667025 | Issue Tracking | |
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/CheckUser/+/667027 | Issue Tracking | |
https://phabricator.wikimedia.org/T275669 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mediawiki Search vendor "Mediawiki" | Mediawiki Search vendor "Mediawiki" for product "Mediawiki" | <= 1.35.2 Search vendor "Mediawiki" for product "Mediawiki" and version " <= 1.35.2" | - |
Affected
|