SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-8001

The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not restrict the uploaded data to the claimed file size, which allows remote authenticated users to cause a denial of service via a chunk…

LOW 3.5EPSS 1.57%

Does this matter?

Lower severity and a low EPSS score (1.57%). Track it; it rarely justifies an emergency change on its own.

Description

The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not restrict the uploaded data to the claimed file size, which allows remote authenticated users to cause a denial of service via a chunk that exceeds the file size.

CVSS 2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
EPSS
1.57% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-284
Affected
mediawiki/mediawiki
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.