Red Hat Bugzilla – Bug 1634161
CVE-2018-0503 mediawiki: $wgRateLimits (rate limit / ping limiter) entry for 'user' overrides that for 'newbie'
Last modified: 2018-09-28 16:49:17 EDT
As reported: Contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'. For example, with the following configuration, newly registered accounts are able to edit 10 pages per hour instead of 5: $wgRateLimits[ 'edit' ] = [ 'user' => [ 10, 60*60 ], 'newbie' => [ 5, 60*60 ], ]; This seems to be the opposite of what documentation in DefaultSettings.php says: 'newbie' => [ x, y ], // each new autoconfirmed accounts; overrides 'user' (although that should probably be 'non-autoconfirmed'…). Upstream bug: https://phabricator.wikimedia.org/T169545 References: https://lists.wikimedia.org/pipermail/mediawiki-announce/2018-September/000223.html
Created mediawiki tracking bugs for this issue: Affects: fedora-all [bug 1634162]