Page MenuHomePhabricator

Tracking bug for MediaWiki 1.35.10/1.38.6/1.39.3
Closed, ResolvedPublic

Description

Previous work: {T318965}

Tracking bug for next security release, 1.35.10/1.38.6/1.39.3

Note: Added T326946: CVE-2020-36649: Bundled PapaParse copy in VisualEditor has known ReDos for a possible mention within the next release, even though it's already public and very wikimedia-specific.

Event Timeline

Reedy renamed this task from Tracking bug for MediaWiki 1.35.10/1.38.6/1.39.2 to Tracking bug for MediaWiki 1.35.10/1.38.6/1.39.3.Feb 21 2023, 4:06 PM
Reedy updated the task description. (Show Details)
Reedy claimed this task.
Reedy changed the visibility from "acl*security (Project)" to "Public (No Login Required)".Apr 4 2023, 4:59 PM
Reedy changed the edit policy from "acl*security (Project)" to "All Users".

Change 905671 had a related patch set uploaded (by Reedy; author: Reedy):

[mediawiki/core@REL1_35] RELEASE-NOTES-1.35: Add CVEs

https://gerrit.wikimedia.org/r/905671

Change 905672 had a related patch set uploaded (by Reedy; author: Reedy):

[mediawiki/core@REL1_38] RELEASE-NOTES-1.38: Add CVE number

https://gerrit.wikimedia.org/r/905672

Change 905673 had a related patch set uploaded (by Reedy; author: Reedy):

[mediawiki/core@REL1_39] RELEASE-NOTES-1.39: Add CVE number

https://gerrit.wikimedia.org/r/905673

Change 905672 merged by jenkins-bot:

[mediawiki/core@REL1_38] RELEASE-NOTES-1.38: Add CVE number

https://gerrit.wikimedia.org/r/905672

Change 905671 merged by jenkins-bot:

[mediawiki/core@REL1_35] RELEASE-NOTES-1.35: Add CVE number

https://gerrit.wikimedia.org/r/905671

Change 905673 merged by jenkins-bot:

[mediawiki/core@REL1_39] RELEASE-NOTES-1.39: Add CVE number

https://gerrit.wikimedia.org/r/905673