CVE-2024-34502: Fedoraproject Fedora

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.

Affected products

  • Fedoraproject Fedora: version 40 only
  • Mediawiki Mediawiki: before 1.39.6 (fixed in 1.39.6); from 1.40.0, before 1.40.2 (fixed in 1.40.2); from 1.41.0, before 1.41.1 (fixed in 1.41.1)

Published 2024-05-05. Last modified 2026-06-17.