Possible to circumvent title-blacklist
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated May 15, 2024
Package
Affected versions
>= 1.31.0, < 1.31.6
>= 1.32.0, < 1.32.6
>= 1.33.0, < 1.33.2
>= 1.33.99, < 1.34.0
Patched versions
1.31.6
1.32.6
1.33.2
1.34.0
Description
Published by the National Vulnerability Database
Dec 11, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
May 15, 2024
Last updated
May 15, 2024
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.
References