Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*", "matchCriteriaId": "FE35D692-87E9-4982-AA23-27EBD5E5EEE1", "versionEndIncluding": "1.23.10", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.24.0:*:*:*:*:*:*:*", "matchCriteriaId": "0B21EB21-AE87-48BF-B4A1-5E63A2E116B4", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.24.1:*:*:*:*:*:*:*", "matchCriteriaId": "A6C00423-B3FE-485A-9014-22F409DBD377", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.24.2:*:*:*:*:*:*:*", "matchCriteriaId": "E90C95FB-71CA-4CA1-935D-58A08244A81F", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.24.3:*:*:*:*:*:*:*", "matchCriteriaId": "5DDBD41F-C2D5-4D7C-B069-FBC2C8EBB81C", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.25.0:*:*:*:*:*:*:*", "matchCriteriaId": "9129F374-93CB-43CE-A3B2-DB6483514F32", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.25.1:*:*:*:*:*:*:*", "matchCriteriaId": "CE125142-10A2-4ACF-9BA4-44E63C1E5DB6", "vulnerable": true}, {"criteria": "cpe:2.3:a:mediawiki:mediawiki:1.25.2:*:*:*:*:*:*:*", "matchCriteriaId": "DF21D6EE-CEAC-42A7-99B6-D9D033E1FEC6", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "The chunked upload API (ApiUpload) in MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not restrict the uploaded data to the claimed file size, which allows remote authenticated users to cause a denial of service via a chunk that exceeds the file size."}, {"lang": "es", "value": "La API chunked upload (ApiUpload) en MediaWiki en versiones anteriores a 1.23.11, 1.24.x en versiones anteriores a 1.24.4 y 1.25.x en versiones anteriores a 1.25.3 no restringe los datos subidos al tama\u00f1o de archivo declarado, lo que permite a usuarios remotos autenticados causar una denegaci\u00f3n de servicio a trav\u00e9s de un fragmento que excede del tama\u00f1o de archivo."}], "id": "CVE-2015-8001", "lastModified": "2025-04-12T10:46:40.837", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "LOW", "cvssData": {"accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "PARTIAL", "baseScore": 3.5, "confidentialityImpact": "NONE", "integrityImpact": "NONE", "vectorString": "AV:N/AC:M/Au:S/C:N/I:N/A:P", "version": "2.0"}, "exploitabilityScore": 6.8, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}]}, "published": "2015-11-09T18:59:00.113", "references": [{"source": "cve@mitre.org", "url": "http://www.securitytracker.com/id/1034028"}, {"source": "cve@mitre.org", "tags": ["Patch", "Vendor Advisory"], "url": "https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000181.html"}, {"source": "cve@mitre.org", "tags": ["Vendor Advisory"], "url": "https://phabricator.wikimedia.org/T91203"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securitytracker.com/id/1034028"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Patch", "Vendor Advisory"], "url": "https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000181.html"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "https://phabricator.wikimedia.org/T91203"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-284"}], "source": "nvd@nist.gov", "type": "Primary"}]}