Denial of Service Vulnerability in Special:MovePage
CVE-2024-34506

7.5HIGH

Key Information:

Vendor

MediaWiki

Status
Vendor
CVE Published:
5 May 2024

What is CVE-2024-34506?

A denial of service vulnerability exists in MediaWiki that can be exploited by users with appropriate permissions. When a user attempts to move a page containing a large number of subpages using the Special:MovePage feature, the request may exceed the server's maximum processing time. This can lead to service disruption, affecting the availability of the MediaWiki platform for users. It's essential for system administrators to apply necessary updates to mitigate this vulnerability and ensure continued functionality of their MediaWiki installations.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.