Page MenuHomePhabricator

MediaWiki 1.24.0 cannot load JavaScript
Closed, InvalidPublic

Description

Yesterday I update my MediaWiki to 1.24.0. JavaScript is no longer loaded. I find a 500 request error when loading the page.

500 http://xuexiii.org/wiki/load.php?debug=false&lang=zh-cn&modules=startup&only=scripts&skin=passion&*

Event Timeline

guoyunhebrave raised the priority of this task from to Needs Triage.
guoyunhebrave updated the task description. (Show Details)
guoyunhebrave changed Security from none to Software security bug.
guoyunhebrave subscribed.
Restricted Application changed the visibility from "Public (No Login Required)" to "Custom Policy". · View Herald TranscriptNov 28 2014, 8:02 AM
Restricted Application changed the edit policy from "All Users" to "Custom Policy". · View Herald Transcript
Restricted Application added a project: acl*security. · View Herald Transcript
Aklapper changed the task status from Open to Stalled.Dec 3 2014, 4:22 PM
Aklapper subscribed.

Thanks for taking the time to report this!

Could you elaborate why this is a security issue and how someone could abuse the problem in a bad way?

500 Internal Server Error is a generic error message.
Have you brought this up on https://www.mediawiki.org/wiki/Project:Support_desk already and followed https://www.mediawiki.org/wiki/Manual:How_to_debug ?
I have not seen other reports about this so this might be a configuration issue instead of a bug.
From which MediaWiki version did you upgrade?
What are steps to reproduce and see the problem on your wiki?
How is the link that you have provided here related?

Restricted Application changed the visibility from "Custom Policy" to "Custom Policy". · View Herald TranscriptDec 3 2014, 4:22 PM
Restricted Application changed the edit policy from "Custom Policy" to "Custom Policy". · View Herald Transcript
guoyunhebrave claimed this task.

It is caused by an old version of Mantle extension. After updated this extension to latest version, the problem was solved.

https://www.mediawiki.org/wiki/Extension:Mantle

Restricted Application changed the visibility from "Custom Policy" to "Custom Policy". · View Herald TranscriptDec 3 2014, 6:22 PM
Restricted Application changed the edit policy from "Custom Policy" to "Custom Policy". · View Herald Transcript
Legoktm changed the task status from Resolved to Invalid.Dec 3 2014, 6:31 PM
Legoktm edited projects, added MediaWiki-General; removed acl*security.
Legoktm changed the visibility from "Custom Policy" to "Public (No Login Required)".
Legoktm changed the edit policy from "Custom Policy" to "All Users".
Legoktm changed Security from Software security bug to None.