Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Resolved | None | T108064 MediaWiki Security release 1.25.3 | |||
Resolved | • csteipp | T91850 No rate limits on uploading files | |||
Resolved | Anomie | T91205 ApiUpload needs sanity check on chunk size | |||
Resolved | • csteipp | T95589 Users with viewsuppressed but not suppressrevision can remove suppression | |||
Resolved | • dpatrick | T108616 Local path disclosure when using ImageMagick as a scaler | |||
Resolved | Legoktm | T110553 Echo ignores hideuser for non-revision based notifications (e.g. thanks) | |||
Resolved | Anomie | T91203 ApiUpload allows overrun without error | |||
Resolved | • Catrope | T111029 XSS possible in PageTriage toolbar | |||
Resolved | • csteipp | T103022 OAuth IP restrictions only apply to Special:OAuth/initiate, not to general API requests | |||
Resolved | • csteipp | T103023 API requests don't get validated if signed by the correct OAuth consumer |
MediaWiki Security release 1.25.3
MediaWiki Security release 1.25.3