Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7w48-ffwf-583v

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not restrict the uploaded data to the claimed file size, which allows remote authenticated users to cause a denial of service via a chunk that exceeds the file size.

The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not restrict the uploaded data to the claimed file size, which allows remote authenticated users to cause a denial of service via a chunk that exceeds the file size.

EPSS

Процентиль: 55%
0.00324
Низкий

Дефекты

CWE-284

Связанные уязвимости

ubuntu
около 10 лет назад

The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not restrict the uploaded data to the claimed file size, which allows remote authenticated users to cause a denial of service via a chunk that exceeds the file size.

nvd
около 10 лет назад

The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not restrict the uploaded data to the claimed file size, which allows remote authenticated users to cause a denial of service via a chunk that exceeds the file size.

debian
около 10 лет назад

The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x ...

EPSS

Процентиль: 55%
0.00324
Низкий

Дефекты

CWE-284