Debian Package Tracker
Register | Log in
Subscribe

mediawiki

website engine for collaborative work

Choose email to subscribe with

general
  • source: mediawiki (main)
  • version: 1:1.43.1+dfsg-2
  • maintainer: MediaWiki packaging team (DMD)
  • uploaders: Kunal Mehta [DMD] – Taavi Väänänen [DMD]
  • arch: all
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1:1.31.16-1+deb10u2
  • o-o-sec: 1:1.31.16-1+deb10u8
  • oldstable: 1:1.35.13-1+deb11u2
  • old-sec: 1:1.35.13-1+deb11u3
  • old-bpo: 1:1.39.1-2~bpo11+1
  • stable: 1:1.39.12-1~deb12u1
  • stable-sec: 1:1.39.12-1~deb12u1
  • testing: 1:1.43.1+dfsg-2
  • unstable: 1:1.43.1+dfsg-2
versioned links
  • 1:1.31.16-1+deb10u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:1.31.16-1+deb10u8: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:1.35.13-1+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:1.35.13-1+deb11u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:1.39.1-2~bpo11+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:1.39.12-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:1.43.1+dfsg-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • mediawiki (2 bugs: 0, 0, 2, 0)
  • mediawiki-classes
action needed
7 security issues in bullseye high

There are 7 open security issues in bullseye.

7 important issues:
  • CVE-2025-3469: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLMultiSelectField.Php. This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.
  • CVE-2025-32072: Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki Core - Feed Utils allows WebView Injection.This issue affects Mediawiki Core - Feed Utils: from 1.39 through 1.43.
  • CVE-2025-32696: Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/actions/RevertAction.Php, includes/api/ApiFileRevert.Php. This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.
  • CVE-2025-32697: Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/editpage/IntroMessageBuilder.Php, includes/Permissions/PermissionManager.Php, includes/Permissions/RestrictionStore.Php. This issue affects MediaWiki: before 1.42.6, 1.43.1.
  • CVE-2025-32698: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/logging/LogPager.Php. This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.
  • CVE-2025-32699: Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid.This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1; Parsoid: before 0.16.5, 0.19.2, 0.20.2.
  • CVE-2025-32700: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/Api/QueryAbuseLog.Php, includes/Pager/AbuseLogPager.Php, includes/Special/SpecialAbuseLog.Php, includes/View/AbuseFilterViewExamine.Php. This issue affects AbuseFilter: from >= 1.43.0 before 1.43.1.
Created: 2025-04-10 Last update: 2025-05-17 14:34
2 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 67d7c3dc0729813c051379daeef270445daf5839
Merge: 696c56bb 063ed090
Author: Kunal Mehta <legoktm@debian.org>
Date:   Sat May 10 16:39:55 2025 +0000

    Merge branch 'description' into 'master'
    
    Update package description
    
    See merge request mediawiki-team/mediawiki!4

commit 063ed090b9b51c76f433f577c1cb03f66e648ce2
Author: Lucas Werkmeister <mail@lucaswerkmeister.de>
Date:   Sat May 10 12:12:09 2025 +0200

    Update package description
    
    Magic links, including ISBN links, have been turned off by default since
    Wikimedia Gerrit change I66b2c4424b / MediaWiki core commit 91e5e41325
    (first shipped upstream in MediaWiki 1.28; first distributed in Debian
    10 (Buster) as part of MediaWiki 1.31, if I’m not mistaken). Let’s
    replace them with templating as a noteworthy feature.
Created: 2025-05-10 Last update: 2025-05-26 00:04
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • mediawiki-classes could be marked Multi-Arch: foreign
Created: 2016-09-14 Last update: 2025-05-25 23:56
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2025-32072: (postponed; to be fixed through a stable update) Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki Core - Feed Utils allows WebView Injection.This issue affects Mediawiki Core - Feed Utils: from 1.39 through 1.43.

You can find information about how to handle this issue in the security team's documentation.

Created: 2025-04-17 Last update: 2025-05-17 14:34
debian/patches: 1 patch to forward upstream low

Among the 7 debian patches available in version 1:1.43.1+dfsg-2 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2025-04-18 Last update: 2025-04-18 17:34
news
[rss feed]
  • [2025-04-29] mediawiki 1:1.43.1+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2025-04-18] Accepted mediawiki 1:1.43.1+dfsg-2 (source) into unstable (Kunal Mehta)
  • [2025-04-14] Accepted mediawiki 1:1.39.12-1~deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Kunal Mehta)
  • [2025-04-13] Accepted mediawiki 1:1.39.12-1~deb12u1 (source) into stable-security (Debian FTP Masters) (signed by: Kunal Mehta)
  • [2025-04-13] mediawiki 1:1.43.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-10] Accepted mediawiki 1:1.43.1+dfsg-1 (source) into unstable (Taavi Väänänen)
  • [2025-04-07] mediawiki 1:1.43.0+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2025-04-05] Accepted mediawiki 1:1.43.0+dfsg-2 (source) into unstable (Taavi Väänänen)
  • [2025-04-04] Accepted mediawiki 1:1.43.0+dfsg-1 (source) into unstable (Taavi Väänänen)
  • [2024-12-30] mediawiki REMOVED from testing (Debian testing watch)
  • [2024-10-06] Accepted mediawiki 1:1.39.10-1~deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Taavi Väänänen)
  • [2024-10-05] Accepted mediawiki 1:1.39.10-1~deb12u1 (source) into stable-security (Debian FTP Masters) (signed by: Taavi Väänänen)
  • [2024-10-04] mediawiki 1:1.39.10-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-01] Accepted mediawiki 1:1.39.10-1 (source) into unstable (Taavi Väänänen)
  • [2024-09-26] Accepted mediawiki 1:1.35.13-1+deb11u3 (source) into oldstable-security (Adrian Bunk)
  • [2024-07-02] mediawiki 1:1.39.8-1 MIGRATED to testing (Debian testing watch)
  • [2024-06-30] Accepted mediawiki 1:1.39.8-1 (source) into unstable (Kunal Mehta)
  • [2024-04-27] Accepted mediawiki 1:1.31.16-1+deb10u8 (source) into oldoldstable (Guilhem Moulin)
  • [2024-04-02] Accepted mediawiki 1:1.35.13-1+deb11u2 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Kunal Mehta)
  • [2024-04-01] Accepted mediawiki 1:1.39.7-1~deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Kunal Mehta)
  • [2024-04-01] mediawiki 1:1.39.7-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-01] mediawiki 1:1.39.7-1 MIGRATED to testing (Debian testing watch)
  • [2024-03-31] Accepted mediawiki 1:1.39.7-1~deb12u1 (source) into stable-security (Debian FTP Masters) (signed by: Kunal Mehta)
  • [2024-03-31] Accepted mediawiki 1:1.35.13-1+deb11u2 (source) into oldstable-security (Debian FTP Masters) (signed by: Kunal Mehta)
  • [2024-03-29] Accepted mediawiki 1:1.39.7-1 (source) into unstable (Taavi Väänänen)
  • [2023-12-30] mediawiki 1:1.39.6-1 MIGRATED to testing (Debian testing watch)
  • [2023-12-27] Accepted mediawiki 1:1.39.6-1 (source) into unstable (Taavi Väänänen)
  • [2023-11-28] Accepted mediawiki 1:1.31.16-1+deb10u7 (source) into oldoldstable (Guilhem Moulin)
  • [2023-10-14] mediawiki 1:1.39.5-1 MIGRATED to testing (Debian testing watch)
  • [2023-10-14] mediawiki 1:1.39.5-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 3
  • RC: 0
  • I&N: 1
  • M&W: 2
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1:1.43.1+dfsg-2
  • 9 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing