User Details
- User Since
- Nov 5 2021, 2:54 PM (239 w, 1 d)
- Availability
- Available
- LDAP User
- Unknown
- MediaWiki User
- MMartorana (WMF) [ Global Accounts ]
Fri, Jun 5
Wed, May 13
May 7 2026
Apr 1 2026
Mar 25 2026
Mar 24 2026
Mar 23 2026
Mar 16 2026
Weekly stats update:
Mar 13 2026
Mar 6 2026
Mar 4 2026
Mar 3 2026
Mar 2 2026
Weekly stats update:
Feb 27 2026
Feb 20 2026
Feb 19 2026
Feb 16 2026
Feb 13 2026
Feb 10 2026
Feb 6 2026
Feb 5 2026
Feb 3 2026
Thanks for the ping! We’re aware of the rollout timeline.
Jan 27 2026
Jan 23 2026
Security Review Summary - T399459 - 2026-01-23
Jan 21 2026
Hi @Ifrahkhanyaree_WMDE - apologies on behalf of the Security-Team. We’ve reprioritized this review and expect it to be completed by the end of this week.
Jan 20 2026
Jan 9 2026
Email from T404620#11504513 has been sent to various mailing lists:
Jan 8 2026
Hi @Jdrewniak - to help us scope this review, could you clarify the expected deployment window more precisely ?
Jan 7 2026
Dec 16 2025
Hey cloud-services-team and @dcaro - this service has a known vulnerability. Since there are currently no mitigation steps and no identified code owner, the Security-Team strongly recommends shutting the service down.
Dec 15 2025
Dec 8 2025
Given the scope, I think it seems reasonable to start with a simple lookup table that maps known AAGUIDs to readable device names (e.g. Google Password Manager, iCloud Keychain, YubiKey 5 Series, etc...). This can be either hardcoded at first, or stored in a small static file. I think that is a good starting point rather than some more complex approach for now.
Dec 2 2025
Dec 1 2025
Hey @Petrb - based on the codepath above this still looks like a plausible SQL injection vector. Could you confirm whether you plan to patch this upstream, or if there’s anything needed from our side to help move it forward?