Debian 9821 Published by

A mediawiki security update has been released for Debian GNU/Linux 10 LTS to address multiple vulnerabilities.

[SECURITY] [DLA 3671-1] mediawiki security update

Debian LTS Advisory DLA-3671-1 Guilhem Moulin
November 28, 2023

Package : mediawiki
Version : 1:1.31.16-1+deb10u7
CVE ID : CVE-2023-3550 CVE-2023-45362 CVE-2023-45363

Multiple vulnerabilities were found in mediawiki, a website engine for
collaborative work, that could lead to information disclosure, privilege
escalation, or denial of service.


Carlos Bello reported a stored cross-site scripting (XSS)
vulnerability when uploading crafted XML file to Special:Upload,
which can lead to privilege escalation. (However .xml file uploads
are not allowed in the default configuration.)


Tobias Frei discovered that diff-multi-sameuser (“X intermediate
revisions by the same user not shown”) ignores username suppression,
which can lead to information leak.


It was discovered that querying pages redirected to other variants
with `redirects` and `converttitles` parameters set would cause
a denial of service (unbounded loop and RequestTimeoutException).

For Debian 10 buster, these problems have been fixed in version

We recommend that you upgrade your mediawiki packages.

For the detailed security status of mediawiki please refer to
its security tracker page at:

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: