CVE-2021-42040

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/10/2021
Last modified:
14/10/2021

Description

An issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allowed for an infinite loop (and php-fpm hang) within the Loops extension because egLoopsCountLimit is mishandled. This could lead to memory exhaustion.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:* 1.36.2 (including)