An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppression blocks are not properly implemented.
The product does not handle or incorrectly handles an exceptional condition.
Link | Tags |
---|---|
https://phabricator.wikimedia.org/T281972 | issue tracking patch vendor advisory exploit |
https://gerrit.wikimedia.org/r/q/I3e65690695313380c798b62edfda726b6e374f89 | patch vendor advisory |
https://gerrit.wikimedia.org/r/q/I15d14c88a1e30df92c470bc191c4ee573172d4d1 | patch vendor advisory |