An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. During item merging, ItemMergeInteractor does not have an edit filter running (e.g., AbuseFilter).
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Link | Tags |
---|---|
https://phabricator.wikimedia.org/T345064 | issue tracking permissions required |
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Wikibase/+/961264 | vendor advisory issue tracking |