Skip to content

ReDoS in DynamicPageList3

Moderate
Universal-Omega published GHSA-8f24-q75c-jhf4 Oct 4, 2021

Package

DynamicPageList3 (MediaWiki extension)

Affected versions

<= 3.3.5

Patched versions

3.3.6

Description

Impact

Unsanitised input of regular expression date within the parameters of the DPL parser function, allowed for the possibility of ReDoS (Regex Denial of Service).

Patches

Upgrade to version 3.3.6 (requires MediaWiki 1.36.0 or later)

Workarounds

Set $wgDplSettings['functionalRichness'] = 0; or disable DynamicPageList3.

For more information

If you have any questions or comments about this advisory:

Severity

Moderate
5.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE ID

CVE-2021-41118

Weaknesses