Page MenuHomePhabricator

Mstyles (Maryum)
User

Projects (7)

Today

  • Clear sailing ahead.

Tomorrow

  • Clear sailing ahead.

Tuesday

  • Clear sailing ahead.

User Details

User Since
Nov 18 2019, 7:30 PM (239 w, 6 d)
Availability
Available
LDAP User
Mstyles
MediaWiki User
MStyles (WMF) [ Global Accounts ]

Recent Activity

Mon, Jun 17

Mstyles added a comment to T364302: Start the Mitre CNA Partner Process for the Wikimedia Foundation .

Great, I think this is the final scope: "Any code repository hosted under gerrit.wikimedia.org, gitlab.wikimedia.org or github.com/wikimedia that is not archived or a fork of an upstream project or otherwise unmaintained by the WMF or Wikimedia Community"

Mon, Jun 17, 4:53 PM · Security-Team

Fri, Jun 14

Mstyles added a comment to T364302: Start the Mitre CNA Partner Process for the Wikimedia Foundation .

I like that, but I do think that we might either have to remove active or define what that means. Do we mean active in the last 6 months? Last year?

Fri, Jun 14, 9:54 PM · Security-Team
Mstyles added a comment to T364302: Start the Mitre CNA Partner Process for the Wikimedia Foundation .

There needs to be clarity on what projects we will manage or not. Originally when we started this project we did say Mediawiki core, skins, and extensions, but if you want to open it up that's fine with me. I'm fine to say vulnerabilities in software maintained by the Wikimedia Foundation or something like that.

Fri, Jun 14, 4:53 PM · Security-Team
Mstyles added a comment to T364302: Start the Mitre CNA Partner Process for the Wikimedia Foundation .

It can't be a minimal list, it needs to be an exact list of what we will issue CVEs for. I'm only saying this because I met with Mitre, and they want a canonical list of what we will and will not cover. We can also say something like, "Scope The GitLab application, any project hosted on GitLab.com in a public repository, and any vulnerabilities discovered by GitLab that are not in another CNA’s scope" but then that might be more broad than we want. Go has one that says, "Vulnerabilities in software published by the Go Project (including the Go standard library, Go toolchain, and the golang.org modules) and publicly disclosed vulnerabilities in publicly importable packages in the Go ecosystem, unless covered by another CNA’s scope". So we could say something very similar to that.

Fri, Jun 14, 4:52 PM · Security-Team
Mstyles added a comment to T364302: Start the Mitre CNA Partner Process for the Wikimedia Foundation .

How about

Fri, Jun 14, 4:43 PM · Security-Team

Thu, Jun 13

Mstyles added a comment to T364302: Start the Mitre CNA Partner Process for the Wikimedia Foundation .

I met with Mitre today and there are two issues to address before we can have the official onboarding meeting with the whole team.
They wanted to get very clear on the scope and we need to have a proper advisory page.

Thu, Jun 13, 11:54 PM · Security-Team

Mon, Jun 10

Mstyles closed T366983: Github MathJax unicode xss exploit as Resolved.

@Physikerwelt thank you for reporting this. This issue looks like it's referring to CVE-2023-39663 which only affects versions of Mathjax under and including 2.7.9. The current version of Mathjax for WMF production is 3.2.2 so WMF systems are not affected. I'm marking this as resolved, but if you have any other questions or comments, please let us know.

Mon, Jun 10, 9:22 PM · Vuln-XSS, Math, Mathoid, Security, Security-Team
Mstyles added a comment to T364302: Start the Mitre CNA Partner Process for the Wikimedia Foundation .

legal approved terms of service in coupa. I'm meeting with Mitre this week to talk about our scope and advisory page. There might need to be some udpates. More to come

Mon, Jun 10, 4:16 PM · Security-Team

Wed, Jun 5

Mstyles closed T366493: Offboard Kelton Hurd from Security Team as Resolved.
Wed, Jun 5, 10:38 PM · SecTeam-Processed, Security-Team
Mstyles updated the task description for T366493: Offboard Kelton Hurd from Security Team.
Wed, Jun 5, 10:38 PM · SecTeam-Processed, Security-Team
Mstyles updated the task description for T366493: Offboard Kelton Hurd from Security Team.
Wed, Jun 5, 10:36 PM · SecTeam-Processed, Security-Team
Mstyles updated the task description for T366493: Offboard Kelton Hurd from Security Team.
Wed, Jun 5, 10:36 PM · SecTeam-Processed, Security-Team

Tue, Jun 4

Mstyles updated the task description for T366493: Offboard Kelton Hurd from Security Team.
Tue, Jun 4, 7:47 PM · SecTeam-Processed, Security-Team
Mstyles updated the task description for T366493: Offboard Kelton Hurd from Security Team.
Tue, Jun 4, 5:50 PM · SecTeam-Processed, Security-Team

Mon, Jun 3

Mstyles added a comment to T364302: Start the Mitre CNA Partner Process for the Wikimedia Foundation .

@acooper I filled out a coupa request with legal

Mon, Jun 3, 9:35 PM · Security-Team

Fri, May 31

Mstyles added a comment to T364302: Start the Mitre CNA Partner Process for the Wikimedia Foundation .

Mitre responded on May 15, but I was OOO so I filled out the CNA registration form today. I did reach out to legal about the terms of service as well. The next steps are for Mitre to schedule a meeting to discuss the program more. If anyone is interested in the onboarding materials, there is information about the onboarding process and the CNA Rules.

Fri, May 31, 2:09 AM · Security-Team

Thu, May 30

Mstyles added projects to T366302: Supply Chain Attack Threat Model: Application Security Reviews, Security.
Thu, May 30, 4:17 PM · Security, Application Security Reviews, secscrum
Mstyles created T366302: Supply Chain Attack Threat Model.
Thu, May 30, 4:17 PM · Security, Application Security Reviews, secscrum

May 16 2024

Mstyles closed T361690: Application Security Review Request : AutoModerator as Resolved.

Security Review Summary - T361690 - 2024-15-05
Last commit reviewed: 54d3a6d

May 16 2024, 7:02 AM · Moderator-Tools-Team, Automoderator, secscrum, Security, Application Security Reviews
Mstyles closed T361690: Application Security Review Request : AutoModerator, a subtask of T361643: Deploy the AutoModerator extension to production (testwiki only), as Resolved.
May 16 2024, 7:01 AM · Moderator-Tools-Team, Automoderator, Wikimedia-extension-review-queue, Wikimedia-Extension-setup

May 15 2024

Mstyles created P62428 Semgrep custom rules.
May 15 2024, 9:31 PM

May 9 2024

Mstyles moved T364560: Update golang gosec security template to use go 1.22 from Incoming to In Progress on the Security-Team board.
May 9 2024, 4:25 PM · SecTeam-Processed, Security-Team, Security, GitLab-Application-Security-Pipeline
Mstyles created T364560: Update golang gosec security template to use go 1.22.
May 9 2024, 4:25 PM · SecTeam-Processed, Security-Team, Security, GitLab-Application-Security-Pipeline

May 7 2024

Mstyles added a comment to T361690: Application Security Review Request : AutoModerator.

@jsn.sherman I'll aim for the end of May for this review, but in case I'm not able to post it, you can go ahead and get the pilot rolling

May 7 2024, 9:58 AM · Moderator-Tools-Team, Automoderator, secscrum, Security, Application Security Reviews

May 6 2024

sbassett awarded T364302: Start the Mitre CNA Partner Process for the Wikimedia Foundation a Like token.
May 6 2024, 4:21 PM · Security-Team
sbassett awarded T353904: Write and send supplementary release announcement for extensions and skins with security patches (1.39.7/1.40.3/1.41.1) a Like token.
May 6 2024, 4:19 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
Mstyles created T364302: Start the Mitre CNA Partner Process for the Wikimedia Foundation .
May 6 2024, 10:15 AM · Security-Team
Mstyles added a comment to T361690: Application Security Review Request : AutoModerator.

@jsn.sherman thank for letting me know, is there a deadline that I should know about for the review? If not, I will post mid June.

May 6 2024, 10:07 AM · Moderator-Tools-Team, Automoderator, secscrum, Security, Application Security Reviews
Mstyles changed the visibility for T353904: Write and send supplementary release announcement for extensions and skins with security patches (1.39.7/1.40.3/1.41.1).
May 6 2024, 10:01 AM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
Mstyles closed T353904: Write and send supplementary release announcement for extensions and skins with security patches (1.39.7/1.40.3/1.41.1) as Resolved.

Supplemental announcement is out!

May 6 2024, 10:01 AM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
Mstyles closed T353904: Write and send supplementary release announcement for extensions and skins with security patches (1.39.7/1.40.3/1.41.1), a subtask of T353894: Release MediaWiki 1.39.7/1.40.3/1.41.1, as Resolved.
May 6 2024, 10:01 AM · MediaWiki-Releasing, Security
Mstyles added a comment to T353904: Write and send supplementary release announcement for extensions and skins with security patches (1.39.7/1.40.3/1.41.1).

Subject: MediaWiki Extensions and Skins Security Release Supplement (1.39.7/1.40.3/1.41.1)

May 6 2024, 9:53 AM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
Mstyles updated the task description for T353904: Write and send supplementary release announcement for extensions and skins with security patches (1.39.7/1.40.3/1.41.1).
May 6 2024, 9:13 AM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
Mstyles renamed T356190: CVE-2024-34503: ReportIncident REST API does not use a CSRF token from CVE-2024-34501: ReportIncident REST API does not use a CSRF token to CVE-2024-34503: ReportIncident REST API does not use a CSRF token.
May 6 2024, 9:12 AM · MW-1.42-notes (1.42.0-wmf.17; 2024-02-06), Trust and Safety Product Sprint (Sprint Kazoo (Jan 29 - Feb 9 2024)), Trust and Safety Product Team, Incident-Reporting-System, Security, Security-Team
Mstyles renamed T355434: CVE-2024-34505: Temporary account IP reveal does not check the deleted status of the performer before revealing the IP address associated with an edit/log event from Temporary account IP reveal does not check the deleted status of the performer before revealing the IP address associated with an edit/log event to CVE-2024-34505: Temporary account IP reveal does not check the deleted status of the performer before revealing the IP address associated with an edit/log event.
May 6 2024, 9:09 AM · MW-1.42-notes (1.42.0-wmf.17; 2024-02-06), Trust and Safety Product Sprint (Sprint Kazoo (Jan 29 - Feb 9 2024)), SecTeam-Processed, Temporary accounts, CheckUser, Trust and Safety Product Team, Security
Mstyles renamed T356183: CVE-2024-34504: IPInfo REST APIs are not safe from CSRF attacks from IPInfo REST APIs are not safe from CSRF attacks to CVE-2024-34504: IPInfo REST APIs are not safe from CSRF attacks.
May 6 2024, 9:08 AM · Trust and Safety Product Sprint (Sprint Piano (Feb 19th - 1st March)), MW-1.42-notes (1.42.0-wmf.19; 2024-02-20), Patch-For-Review, Vuln-CSRF, SecTeam-Processed, IP Info, Trust and Safety Product Team, Security, Security-Team
Mstyles renamed T357101: CVE-2024-34502: Special:MergeLexemes makes edits on GET requests without edit tokens from Special:MergeLexemes makes edits on GET requests without edit tokens to CVE-2024-34502: Special:MergeLexemes makes edits on GET requests without edit tokens.
May 6 2024, 9:02 AM · MW-1.42-notes (1.42.0-wmf.23; 2024-03-19), Vuln-CSRF, SecTeam-Processed, Wikidata Dev Team (Wikidata.org Slice), Wikidata Lexicographical data, Wikidata, Security, Security-Team
Mstyles renamed T356190: CVE-2024-34503: ReportIncident REST API does not use a CSRF token from ReportIncident REST API does not use a CSRF token to CVE-2024-34501: ReportIncident REST API does not use a CSRF token.
May 6 2024, 9:00 AM · MW-1.42-notes (1.42.0-wmf.17; 2024-02-06), Trust and Safety Product Sprint (Sprint Kazoo (Jan 29 - Feb 9 2024)), Trust and Safety Product Team, Incident-Reporting-System, Security, Security-Team
Mstyles renamed T357203: CVE-2024-34500: XSS through interface message in UnlinkedWikibase from XSS through interface message in UnlinkedWikibase to CVE-2024-34500: XSS through interface message in UnlinkedWikibase.
May 6 2024, 8:57 AM · Vuln-XSS, SecTeam-Processed, MediaWiki-extensions-UnlinkedWikibase, affects-Miraheze, Security, Security-Team

Apr 23 2024

Mstyles added a comment to T362588: Classic CSRF in MediaWikiChat's API modules.

@ashley Since MediaWikiChat is not deployed in WMF production, this patch can be pushed through github.

Apr 23 2024, 3:18 PM · security-bug, SecTeam-Processed, Vuln-CSRF, MediaWikiChat, Security
Mstyles closed T363068: Please remove 2FA from Vito Genovese Wikimedia SUL account as Declined.
Apr 23 2024, 3:18 PM · SecTeam-Processed, Trust-and-Safety, Security
Mstyles changed the visibility for T363068: Please remove 2FA from Vito Genovese Wikimedia SUL account.
Apr 23 2024, 3:16 PM · SecTeam-Processed, Trust-and-Safety, Security

Apr 15 2024

Mstyles closed T362199: Security Issue Access Request for jrbranaa as Resolved.

security issue access has been granted

Apr 15 2024, 5:32 PM · SecTeam-Processed, Security-Team, Security
Mstyles added a member for acl*security_management: Jrbranaa.
Apr 15 2024, 5:29 PM

Apr 13 2024

Mstyles created T362460: Pentest FY2023/24 - Fundraising Tech.
Apr 13 2024, 12:20 AM · secscrum
Mstyles created T362459: Pentest FY2023/24 - Kartographer.
Apr 13 2024, 12:17 AM · secscrum

Apr 10 2024

Mstyles reassigned T360070: Application Security Review Request : Extension:IPReputation from Mstyles to sbassett.
Apr 10 2024, 4:34 PM · user-sbassett, MediaWiki-extensions-IPReputation, secscrum, Security, Application Security Reviews

Apr 8 2024

Mstyles added a comment to T361690: Application Security Review Request : AutoModerator.

@Samwalton9-WMF this review will be scoped to the extension only, the models will be out of scope for this review. Is it possible that this tool will replace existing auto moderator tools? For the timeline, does that mean the review can start in May? We're planning to do this review this quarter.

Apr 8 2024, 6:27 PM · Moderator-Tools-Team, Automoderator, secscrum, Security, Application Security Reviews

Apr 5 2024

Mstyles added a comment to T361943: Decide on a Software Bill of Materials (SBOM) format for MediaWiki.

It looks like it's not too bad to convert from CycloneDX to SPDX, so even if we decide to go with CycloneDX we can still get the SPDX data if we want it. CycloneDX seems to have more tooling and also provides a license scanner to look at the licenses @Jdforrester-WMF was referencing.

Apr 5 2024, 6:30 PM · SecTeam-Processed, Security-Team, Security

Apr 2 2024

Mstyles moved T361260: Add limits to loop condition from Incoming to Watching on the Security-Team board.
Apr 2 2024, 5:48 PM · MW-1.43-notes (1.43.0-wmf.1; 2024-04-16), Security-Team, Security, function-schemata, Abstract Wikipedia Fix-It tasks, Abstract Wikipedia team
Mstyles added a project to T361260: Add limits to loop condition: Security-Team.
Apr 2 2024, 5:48 PM · MW-1.43-notes (1.43.0-wmf.1; 2024-04-16), Security-Team, Security, function-schemata, Abstract Wikipedia Fix-It tasks, Abstract Wikipedia team
Mstyles edited projects for T361260: Add limits to loop condition, added: Security; removed secscrum.
Apr 2 2024, 5:47 PM · MW-1.43-notes (1.43.0-wmf.1; 2024-04-16), Security-Team, Security, function-schemata, Abstract Wikipedia Fix-It tasks, Abstract Wikipedia team

Mar 29 2024

Mstyles claimed T353904: Write and send supplementary release announcement for extensions and skins with security patches (1.39.7/1.40.3/1.41.1).
Mar 29 2024, 12:28 AM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Mar 28 2024

Mstyles closed T353827: Pentest FY2023/24 - Wikifunctions as Resolved.

Resolving this ticket as the report has been delivered and reviewed by the team

Mar 28 2024, 5:00 PM · Abstract Wikipedia team, secscrum
Mstyles closed T353828: Pentest FY2023/24 - LiftWing as Resolved.

Team has confirmed that there are no action items from the report

Mar 28 2024, 5:00 PM · secscrum
Mstyles updated the task description for T353827: Pentest FY2023/24 - Wikifunctions.
Mar 28 2024, 4:58 PM · Abstract Wikipedia team, secscrum
Mstyles created T361260: Add limits to loop condition.
Mar 28 2024, 4:58 PM · MW-1.43-notes (1.43.0-wmf.1; 2024-04-16), Security-Team, Security, function-schemata, Abstract Wikipedia Fix-It tasks, Abstract Wikipedia team
Mstyles closed T358619: Security Issue Access Request for SGupta-WMF as Resolved.

security issue access has been granted.

Mar 28 2024, 4:34 PM · SecTeam-Processed, Data Products, Security-Team, Security
Mstyles added a member for Security: SGupta-WMF.
Mar 28 2024, 4:33 PM
Mstyles added a member for acl*security_developer: SGupta-WMF.
Mar 28 2024, 4:33 PM

Mar 27 2024

Mstyles closed T353826: Pentest FY2023/24 - Wikipedia Library as Resolved.

Report has been released, gone over with the team and subtasks created so I'm resolving this ticket.

Mar 27 2024, 11:36 PM · The-Wikipedia-Library, secscrum
Mstyles added a comment to T353828: Pentest FY2023/24 - LiftWing.

The report has been released to team members. Still checking in about any fixes due to the report

Mar 27 2024, 11:35 PM · secscrum
Mstyles added a comment to T351657: Application Security Review Request : Matomo upgrade and its campaign reporter plugin.

@SCampos-WMF thank you, I'll check back

Mar 27 2024, 11:20 PM · SecTeam-Processed, secscrum, Security, Application Security Reviews

Mar 25 2024

Mstyles added a comment to T360504: i18n XSS vulnerability in message 'tux-nojs'.

I updated the existing patch to used escaped instead of parsed. If we agree to move forward with this, I can upload this on gerrit so that we can address this issue faster.

Mar 25 2024, 8:09 PM · SecTeam-Processed, MW-1.42-notes (1.42.0-wmf.25; 2024-04-02), Vuln-XSS, MediaWiki-extensions-Translate, Security, Security-Team

Mar 22 2024

Mstyles updated the task description for T347659: Write and send supplementary release announcement for extensions and skins with security patches (1.35.14/1.39.6/1.40.2/1.41.0).
Mar 22 2024, 8:24 PM · user-sbassett, SecTeam-Processed, MediaWiki-Releasing, Security
Mstyles updated subscribers of T357101: CVE-2024-34502: Special:MergeLexemes makes edits on GET requests without edit tokens.

pushing the rebased patch to gerrit for the supplemental release: https://gerrit.wikimedia.org/r/c/mediawiki/extensions/WikibaseLexeme/+/1013359

Mar 22 2024, 6:42 PM · MW-1.42-notes (1.42.0-wmf.23; 2024-03-19), Vuln-CSRF, SecTeam-Processed, Wikidata Dev Team (Wikidata.org Slice), Wikidata Lexicographical data, Wikidata, Security, Security-Team

Mar 18 2024

Mstyles reassigned T359087: Redirecting @priv_eng_sync Phab account (Asana sync) to new email address from Mstyles to Cleo_Lemoisson.

Reassigning to Cleo to figure this out with the privacy team

Mar 18 2024, 5:10 PM · SecTeam-Processed, Security-Team

Mar 9 2024

Mstyles reopened T351657: Application Security Review Request : Matomo upgrade and its campaign reporter plugin as "Open".

I did do a review for the Matomo upgrade as well since that was requested. I'm reopening this ticket in case you have any questions.

Mar 9 2024, 2:12 AM · SecTeam-Processed, secscrum, Security, Application Security Reviews
Mstyles reopened T351657: Application Security Review Request : Matomo upgrade and its campaign reporter plugin, a subtask of T319013: Enable the Marketing Campaigns Reporting plugin for matomo, as Open.
Mar 9 2024, 2:11 AM · Data-Platform-SRE (2024.03.04 - 2024.03.24), Data-Engineering, Foundational Technology Requests
Mstyles reopened T351657: Application Security Review Request : Matomo upgrade and its campaign reporter plugin, a subtask of T351552: Upgrade matomo (piwik.wikimedia.org) to latest stable version, as Open.
Mar 9 2024, 2:11 AM · Data-Platform-SRE (2024.04.15 - 2024.05.05)

Mar 8 2024

Mstyles closed T358618: Security Issue Access Request for Sfaci as Resolved.

security issue access granted!

Mar 8 2024, 12:39 AM · SecTeam-Processed, Data Products, Security-Team, Security
Mstyles added a member for Security: Sfaci.
Mar 8 2024, 12:39 AM
Mstyles added a member for acl*security_developer: Sfaci.
Mar 8 2024, 12:38 AM
Mstyles added a comment to T359087: Redirecting @priv_eng_sync Phab account (Asana sync) to new email address.

@Aklapper would you be able to update the @priv_eng_sync user so that it points to the email address above? If that's not possible, then I'll go ahead and have that account deleted.

Mar 8 2024, 12:36 AM · SecTeam-Processed, Security-Team
Mstyles added a comment to T358619: Security Issue Access Request for SGupta-WMF.

@SGupta-WMF could you please enable Two-Factor Authentication for your Phabricator account under Settings → Authentication → Multi-Factor Auth and read the warning under https://www.mediawiki.org/wiki/Phabricator/Help/Two-factor_Authentication_Resets ?

Mar 8 2024, 12:35 AM · SecTeam-Processed, Data Products, Security-Team, Security

Mar 6 2024

Mstyles added a comment to T351657: Application Security Review Request : Matomo upgrade and its campaign reporter plugin.

Security Review Summary - T351657 - Matomo Campaign Plugin- 2024-03-06

Mar 6 2024, 8:45 AM · SecTeam-Processed, secscrum, Security, Application Security Reviews

Mar 5 2024

Mstyles added a comment to T359087: Redirecting @priv_eng_sync Phab account (Asana sync) to new email address.

email address we want to try: x+1143023741172261@mail.asana.com

Mar 5 2024, 6:25 PM · SecTeam-Processed, Security-Team
Mstyles added a comment to T357760: CVE-2024-34506: Denial of service vector via GET request to Special:MovePage on pages with thousands of subpages.

@Dreamy_Jazz I'm glad that the patch works. I think adding the hard-coded message once this uploaded is fine. There was an issue with deployment which I wanted to note here: https://phabricator.wikimedia.org/T276237#9598800

Mar 5 2024, 6:50 AM · MW-1.42-notes (1.42.0-wmf.26; 2024-04-09), MW-1.41-notes, MW-1.40-notes, MW-1.39-notes, SecTeam-Processed, Patch-For-Review, MediaWiki-Page-rename, Vuln-DoS, Security, Security-Team

Mar 4 2024

Mstyles added a parent task for T357760: CVE-2024-34506: Denial of service vector via GET request to Special:MovePage on pages with thousands of subpages: T353895: Tracking bug for MediaWiki 1.39.7/1.40.3/1.41.1.
Mar 4 2024, 10:51 PM · MW-1.42-notes (1.42.0-wmf.26; 2024-04-09), MW-1.41-notes, MW-1.40-notes, MW-1.39-notes, SecTeam-Processed, Patch-For-Review, MediaWiki-Page-rename, Vuln-DoS, Security, Security-Team
Mstyles added a subtask for T353895: Tracking bug for MediaWiki 1.39.7/1.40.3/1.41.1: T357760: CVE-2024-34506: Denial of service vector via GET request to Special:MovePage on pages with thousands of subpages.
Mar 4 2024, 10:51 PM · MediaWiki-Releasing, Security
Mstyles moved T357760: CVE-2024-34506: Denial of service vector via GET request to Special:MovePage on pages with thousands of subpages from Security Patch To Deploy to Watching on the Security-Team board.
Mar 4 2024, 10:48 PM · MW-1.42-notes (1.42.0-wmf.26; 2024-04-09), MW-1.41-notes, MW-1.40-notes, MW-1.39-notes, SecTeam-Processed, Patch-For-Review, MediaWiki-Page-rename, Vuln-DoS, Security, Security-Team
Mstyles added a comment to T357760: CVE-2024-34506: Denial of service vector via GET request to Special:MovePage on pages with thousands of subpages.

Proposed patch:

Note: Due to https://wikitech.wikimedia.org/wiki/How_to_deploy_code#Guidelines_for_creating_patches, this patch has a hardcoded message which is used when the list of subpages is truncated.

Mar 4 2024, 10:48 PM · MW-1.42-notes (1.42.0-wmf.26; 2024-04-09), MW-1.41-notes, MW-1.40-notes, MW-1.39-notes, SecTeam-Processed, Patch-For-Review, MediaWiki-Page-rename, Vuln-DoS, Security, Security-Team
Mstyles closed T356297: Offboard James Fishback from Security Team as Resolved.

Moved the privacy engineering sync to a separate ticket

Mar 4 2024, 5:18 PM · SecTeam-Processed, Security-Team
Mstyles updated the task description for T356297: Offboard James Fishback from Security Team.
Mar 4 2024, 5:17 PM · SecTeam-Processed, Security-Team
Mstyles moved T359087: Redirecting @priv_eng_sync Phab account (Asana sync) to new email address from Incoming to In Progress on the Security-Team board.
Mar 4 2024, 5:14 PM · SecTeam-Processed, Security-Team
Mstyles created T359087: Redirecting @priv_eng_sync Phab account (Asana sync) to new email address.
Mar 4 2024, 5:14 PM · SecTeam-Processed, Security-Team

Mar 1 2024

Mstyles added a comment to T348780: Integrate a risk factor related to how many production projects an extension or skin is deployed.

@sbassett this looks really good! glad it's fast since the other methods were not as fast.

Mar 1 2024, 2:45 AM · Patch-For-Review, SecTeam-Processed, Code-Health, Security, Security Team AppSec, production-risk-assessment, Security-Team

Feb 28 2024

Mstyles added subtasks for T353826: Pentest FY2023/24 - Wikipedia Library : Unknown Object (Task), Unknown Object (Task), Unknown Object (Task), Unknown Object (Task), Unknown Object (Task), Unknown Object (Task), Unknown Object (Task), Unknown Object (Task).
Feb 28 2024, 7:05 PM · The-Wikipedia-Library, secscrum
Mstyles merged T358257: Wikipedia Library January 2024 Pentest into T353826: Pentest FY2023/24 - Wikipedia Library .
Feb 28 2024, 7:02 PM · The-Wikipedia-Library, secscrum
Mstyles merged task T358257: Wikipedia Library January 2024 Pentest into T353826: Pentest FY2023/24 - Wikipedia Library .
Feb 28 2024, 7:02 PM · The-Wikipedia-Library, Moderator-Tools-Team, Epic
Mstyles reopened T353826: Pentest FY2023/24 - Wikipedia Library as "In Progress".
Feb 28 2024, 7:02 PM · The-Wikipedia-Library, secscrum
Mstyles merged T353826: Pentest FY2023/24 - Wikipedia Library into T358257: Wikipedia Library January 2024 Pentest.
Feb 28 2024, 7:01 PM · The-Wikipedia-Library, Moderator-Tools-Team, Epic
Mstyles merged task T353826: Pentest FY2023/24 - Wikipedia Library into T358257: Wikipedia Library January 2024 Pentest.
Feb 28 2024, 7:00 PM · The-Wikipedia-Library, secscrum

Feb 27 2024

Mstyles closed T358140: Security Issue Access Request for @MShilova_WMF as Resolved.

Security issue access has been granted

Feb 27 2024, 7:21 PM · SecTeam-Processed, Security-Team, Security
Mstyles added a member for acl*security_program_manager: MShilova_WMF.
Feb 27 2024, 7:20 PM
Mstyles added a member for Security: MShilova_WMF.
Feb 27 2024, 7:19 PM
Mstyles claimed T358140: Security Issue Access Request for @MShilova_WMF .
Feb 27 2024, 12:44 AM · SecTeam-Processed, Security-Team, Security
Mstyles updated the task description for T356297: Offboard James Fishback from Security Team.
Feb 27 2024, 12:37 AM · SecTeam-Processed, Security-Team

Feb 26 2024

Mstyles updated the task description for T356297: Offboard James Fishback from Security Team.
Feb 26 2024, 5:14 PM · SecTeam-Processed, Security-Team
Mstyles updated the task description for T356297: Offboard James Fishback from Security Team.
Feb 26 2024, 5:05 PM · SecTeam-Processed, Security-Team