Impact
Unsanitised input of regular expression date within the parameters of the DPL parser function, allowed for the possibility of ReDoS (Regex Denial of Service).
Patches
Upgrade to version 3.3.6 (requires MediaWiki 1.36.0 or later)
Workarounds
Set $wgDplSettings['functionalRichness'] = 0;
or disable DynamicPageList3.
For more information
If you have any questions or comments about this advisory:
Impact
Unsanitised input of regular expression date within the parameters of the DPL parser function, allowed for the possibility of ReDoS (Regex Denial of Service).
Patches
Upgrade to version 3.3.6 (requires MediaWiki 1.36.0 or later)
Workarounds
Set
$wgDplSettings['functionalRichness'] = 0;
or disable DynamicPageList3.For more information
If you have any questions or comments about this advisory: