CVE-2021-41801

Name
CVE-2021-41801
Description
The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitting a replace job, the job is still run, even if it may be run at a later time (due to the job queue backlog)
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://lists.wikimedia.org/hyperkitty/list/wikitech-l@lists.wikimedia.org/thread/2IFS5CM2YV4VMSODPX3J2LFHKSEWVFV5/
MISC https://phabricator.wikimedia.org/T279090

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* mediawiki >= None < 1.31.16
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* mediawiki >= 1.35.0 < 1.35.4
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* mediawiki >= 1.36.0 < 1.36.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status