VWE-2018-4625 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2018-4625
This page is a chapter in Info Known Vulnerabilities

This page has been seen 202,254 times.

    • Created by on
Common NameNone
VWE-IDVWE-2018-4625
Related ReportNone
SeverityHIGH
Exploit DifficultyNORMAL
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionDenial of Service Amplification. A distributed attack that posts comments to a single wiki discussion may be able to achieve denial of service due to a flaw in the quick reply handler.
DiscoveredJuly 27, 2018
ResolvedAugust 27, 2018
Patches Available4.0.23 Patch Level 2
4.0.22 Patch Level 4
4.0.21 Patch Level 5
4.0.20 Patch Level 8
4.0.19 Patch Level 11
WorkaroundIn the Wiki admin panel, go to Permissions > Usergroups, and make sure that any usergroups that could potentially include large numbers of users do not have permission to post new comments.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.