Page MenuHomePhabricator

Tracking bug for MediaWiki 1.35.6/1.36.4/1.37.2
Closed, ResolvedPublic

Description

Previous work: T292227: Tracking bug for MediaWiki 1.35.5/1.36.3/1.37.1

Tracking bug for next security release, 1.35.6/1.36.4/1.37.2

Maniphest IDCVE IDREL1_35REL1_36REL1_37REL1_38master
T297543CVE-2022-28202mergedmergedmergedmergedmerged
T297571CVE-2022-28201
T297731CVE-2022-28203
T297754CVE-2022-28204n/an/a

Related Objects

Event Timeline

Reedy renamed this task from Tracking bug for MediaWiki 1.35.5/1.36.3/1.37.1 to Tracking bug for MediaWiki 1.35.6/1.36.4/1.37.2.Dec 15 2021, 9:12 PM
Reedy updated the task description. (Show Details)
Reedy updated the task description. (Show Details)
Reedy updated the task description. (Show Details)

So the 3 patches apply fine on master/REL1_38/REL1_37.

The first two (not T297754: CVE-2022-28204: Whatlinkshere of heavily used properties in wikidata can be easily utilized as a DDoS vector) also apply to REL1_36/REL1_35. Need to poke at that one a bit further.

Reedy claimed this task.
Reedy triaged this task as Medium priority.
Reedy changed the visibility from "acl*security (Project)" to "Public (No Login Required)".
Reedy changed the edit policy from "acl*security (Project)" to "All Users".