Fedora 41 MediaWiki Security Advisory: User Control Issues in FEDORA-2025
Summary
MediaWiki is the software used for Wikipedia and the other Wikimedia
Foundation websites. Compared to other wikis, it has an excellent
range of features and support for high-traffic websites using multiple
servers
This package supports wiki farms. Read the instructions for creating wiki
instances under /usr/share/doc/mediawiki/README.RPM.
Remember to remove the config dir after completing the configuration.
Update Information:
https://lists.wikimedia.org/hyperkitty/list/wikitech- l@lists.wikimedia.org/thread/PFTE5RHUERS6KTUGGRZO7XXV5THNJ77E/ https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/5NYC4UZLY3MWQZ6DYJAUQRJG2ZHZFBJ6/
Change Log
* Thu Jan 16 2025 Michael Cronenworth
References
[ 1 ] Bug #2316896 - CVE-2024-47848 mediawiki: User can review/unreview articles while blocked [fedora-40]
https://bugzilla.redhat.com/show_bug.cgi?id=2316896
[ 2 ] Bug #2338424 - CVE on mediawiki 1.41.2
https://bugzilla.redhat.com/show_bug.cgi?id=2338424
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-25b16d6561' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label