Mediawiki security releases 1.39.7, 1.40.3 and 1.41.1. This includes a fix for a denial of service that occurs when a user opens Special:MovePage for a page containing a large number (tens of thousands) of subpages. Due to excessive queries used to create the list of subpages the maximum request time will be exceeded. References: https://phabricator.wikimedia.org/T357760 https://lists.wikimedia.org/hyperkitty/list/wikitech-l@lists.wikimedia.org/thread/V3WXEPXV2DU6WTVEKK4XHW4QXD5OFKD7/
CVE is still pending
Created mediawiki tracking bugs for this issue: Affects: fedora-all [bug 2278774]