Page MenuHomePhabricator

Tracking bug for MediaWiki 1.35.5/1.36.3/1.37.1
Closed, ResolvedPublic

Description

Previous work: T285405: Tracking bug for MediaWiki 1.31.16/1.35.4/1.36.2

Tracking bug for next security release, 1.35.5/1.36.3/1.37.1

n.b. T292763 already landed in mw core master and, therefore, has been disclosed.

n.b. T294686 is for Nuke, which is bundled and deployed, but the vulnerability in this task was only on master for a week or so, so it was technically disclosed early, but should likely be mentioned within the release announcement.

Maniphest IDCVE IDREL1_35REL1_36REL1_37master
T293589CVE-2021-44855
T292763CVE-2021-44854mergedmergedmergedmerged
T294686n/amergedmergedmergedmerged
T271037CVE-2021-44856
T297322CVE-2021-44857, CVE-2021-44858
T297574CVE-2021-45038
T297416n/a

Related Objects

Event Timeline

Reedy renamed this task from Tracking bug for MediaWiki 1.31.16/1.35.4/1.36.2 to Tracking bug for MediaWiki 1.35.5/1.36.3.Sep 30 2021, 6:44 PM
Reedy updated the task description. (Show Details)
Reedy renamed this task from Tracking bug for MediaWiki 1.35.5/1.36.3 to Tracking bug for MediaWiki 1.35.5/1.36.3/1.37.1.Nov 24 2021, 5:19 PM
Reedy updated the task description. (Show Details)
Reedy changed the task status from Open to In Progress.Dec 10 2021, 8:10 PM
Reedy triaged this task as Medium priority.
Reedy claimed this task.