< Wikimedia Security Team

Special thanks to the people who have helped improve the security of MediaWiki, and other software supporting the Wikimedia projects!

Note: This only covers MediaWiki core and bundled extensions. While we deeply appreciate people reporting issues against other extensions, they are not covered by this page.

Todo: Where do we thank people for reporting non-MediaWiki things like parsoid vulns, or varnish config vulns?

CVE Ticket Reporter
MediaWiki 1.29.2, 1.28.3 and 1.27.4 (November 2017)
CVE-2017-8809T128209Abdullah Hussam
noneT165846Anomie
CVE-2017-8810T134100Bartosz Dziewoński ("Matma Rex")
CVE-2017-8808T178451Bawolff
CVE-2017-8811T176247Bastenbas
CVE-2017-8812T125163Bawolff
CVE-2017-8814T124404Bawolff
CVE-2017-8815T119158Bawolff
CVE-2017-0361T180488Anomie
CVE-2017-9841T180231Tom Hutchison
MediaWiki 1.28.1, 1.27.2 and 1.23.16 (April 2017)
CVE-2017-0363T109140Merlijn van Deen (aka "Valhallasw")
CVE-2017-0364T122209Bawolff
CVE-2017-0365T144845Bawolff
CVE-2017-0361T125177Tgr
CVE-2017-0362T150044Legoktm
CVE-2017-0368T156184Bawolff
CVE-2017-0366T151735Cassiogomes11
CVE-2017-0370T48143MZMcBride
CVE-2017-0369T108138Luke081515
CVE-2017-0367T161453Bawolff
CVE-2017-0372T158689Yorick Koster (Securify)
MediaWiki 1.27.1, 1.26.4, 1.23.15 (August 2016)
CVE-2016-6335T139565, T139570This, Schnark
CVE-2016-6334T137264Bawolff, Legoktm
CVE-2016-6333T133147Bawolff
CVE-2016-6336T132926Bawolff
CVE-2016-6332T129738Multichill
CVE-2016-6331T115333Church of emacs
noneT57548PleaseStand
CVE-2016-6337T139670Anomie
MediaWiki 1.26.3, 1.25.6 and 1.23.14 (May 2016)
noneT122056Unicornisaurous
noneT127114Bawolff
noneT123653MaxSem
noneT123071Bawolff
noneT129506eranroz
noneT125283Matiia, Matanya
noneT103239Fomafix
noneT122807User:CSteipp (WMF) (Based on by Paragon Initiative Enterprises Security Team)
noneT130947MaxSem
noneT133507Ori Livneh
noneT110143Bawolff
noneT132874Anomie
noneT127420PleaseStand
noneT126685CSteipp
noneT116030CSteipp
MediaWiki 1.26.1, 1.25.4, 1.24.5 and 1.23.12 (Dec 2015)
CVE-2015-8628T109724Xavier Combelle
CVE-2015-8627T97897Vituzzu
CVE-2015-8626T115522Frank R. Farmer
CVE-2015-8625T118032User:Catrope
CVE-2015-8623gerrit:156336User:Anomie
CVE-2015-8624T119309User:Tgr (WMF)
CVE-2015-8622T117899Bartosz Dziewoński ("Matma Rex")

2016

Contributor Found Fixed
Sergey Belov T118769
Ori Livneh T118769

2015

Contributor Found Fixed
BWolff (WMF) CVE-2015-2933, CVE-2015-2932 CVE-2015-8628, CVE-2015-2933
BJorsch (WMF) CVE-2015-8004 CVE-2015-8623, CVE-2015-8626, CVE-2015-8001, CVE-2015-8002, CVE-2015-6728, CVE-2015-2938, CVE-2015-8004
Brion Vibber (WMF) CVE-2015-6735
Bsadowski1 CVE-2015-6727
CSteipp (WMF) CVE-2015-8003, CVE-2015-6732, CVE-2015-6732, CVE-2015-6728, CVE-2015-6730, CVE-2015-2937, CVE-2015-2934, CVE-2015-2936 CVE-2015-8009, CVE-2015-8008, CVE-2015-8003, CVE-2015-6732, CVE-2015-6731, CVE-2015-6730, CVE-2015-2931, CVE-2015-2937, CVE-2015-2934, CVE-2015-2942, CVE-2015-2932
DPatrick (WMF) CVE-2015-8627, CVE-2015-8005, T98533
Frankrfarmer CVE-2015-8626
Grunny CVE-2015-6731, CVE-2015-8006 CVE-2015-8006
Hoo man CVE-2015-6736
Jackmcbarn CVE-2015-2939 CVE-2015-2939
John Menerick CVE-2015-6729
Legoktm CVE-2015-8007 CVE-2015-6727, CVE-2015-2941, CVE-2015-2940, CVE-2015-8007
Majr CVE-2015-6737
MaxSem CVE-2015-6733 CVE-2015-6734, CVE-2015-6733
McZusatz CVE-2015-6735
DAU Huy Ngoc CVE-2015-6734
Parent5446 CVE-2015-2936, CVE-2015-2935
Roan Kattouw (WMF) CVE-2015-8625 CVE-2015-8625
RobinHood70 CVE-2015-8001
Richard Stanway CVE-2015-8005, CVE-2015-8002
Sitic CVE-2015-8009, CVE-2015-8008
Tgr (WMF) CVE-2015-8624 CVE-2015-8624
Vituzzu CVE-2015-8627
Xavier Combelle CVE-2015-8628
^demon CVE-2015-6736
This article is issued from Mediawiki. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.