In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items. Reference: https://phabricator.wikimedia.org/T296578 Upstream patches: https://gerrit.wikimedia.org/r/q/Id9af124427bcd1e85301d2140a38bf47bbc5622c https://gerrit.wikimedia.org/r/q/Iac86cf63bd014ef99e83dccfce9b8942e15d2bf9
Created mediawiki tracking bugs for this issue: Affects: fedora-all [bug 2036080]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-45471