MediaWiki 1.34
MediaWiki 1.34
The MediaWiki 1.34 reached end of service life on Nov 30, 2020 — MediaWiki no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your MediaWiki 1.34 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- mediawiki
- release
- 1.34
- product Label
- MediaWiki
- release Label
- 1.34
- codename
- lts
- latest Version
- 1.34.4
- release Date
- 2019-12-19
- maintained
- source Url
- https://endoflife.date/mediawiki
Lifecycle Dates
- End of Service Life
- Nov 30, 2020
- Last OEM Support
- Nov 30, 2020
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for MediaWiki 1.34 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for MediaWiki 1.34?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for MediaWiki 1.34 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
MediaWiki 1.34 Support: Frequently Asked Questions
Is the MediaWiki 1.34 still supported?
MediaWiki ended support for the MediaWiki 1.34 on Nov 30, 2020 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the MediaWiki 1.34 end of service life (EOSL) date?
MediaWiki lists the end of service life for the MediaWiki 1.34 as Nov 30, 2020.
Can I keep using the MediaWiki 1.34 after its EOSL date?
Yes. EOSL means MediaWiki stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the MediaWiki 1.34 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting MediaWiki 1.34
181 published CVEs affect the MediaWiki 1.34, including 39 rated critical or high severity. MediaWiki no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2024-34502 | CRITICAL | 9.8 | May 5, 2024 | An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token. |
| CVE-2023-37303 | CRITICAL | 9.8 | Jun 30, 2023 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In certain situations, an attempt to block a user fails after a temporary browser hang and a DBQueryDisconnectedError error message. |
| CVE-2023-29141 | CRITICAL | 9.8 | Mar 31, 2023 | An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header. |
| CVE-2022-29906 | CRITICAL | 9.8 | Apr 29, 2022 | The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user. |
| CVE-2022-29904 | CRITICAL | 9.8 | Apr 29, 2022 | The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints. |
| CVE-2022-28209 | CRITICAL | 9.8 | Mar 30, 2022 | An issue was discovered in Mediawiki through 1.37.1. The check for the override-antispoof permission in the AntiSpoof extension is incorrect. |
| CVE-2022-28206 | CRITICAL | 9.8 | Mar 30, 2022 | An issue was discovered in MediaWiki through 1.37.1. ImportPlanValidator.php in the FileImporter extension mishandles the check for edit rights. |
| CVE-2022-28205 | CRITICAL | 9.8 | Mar 30, 2022 | An issue was discovered in MediaWiki through 1.37.1. The CentralAuth extension mishandles a ttl issue for groups expiring in the future. |
| CVE-2021-31556 | CRITICAL | 9.8 | Aug 12, 2021 | An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an RSA key will fit in a MySQL blob. |
| CVE-2021-36128 | CRITICAL | 9.8 | Jul 2, 2021 | An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppression blocks are not properly implemented. |
| CVE-2021-36126 | CRITICAL | 9.8 | Jul 2, 2021 | An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36. If the MediaWiki:Abusefilter-blocker message is invalid within the content language, the filter user falls back to the English version, but that English version could also be invalid on a wiki. This would result in a fatal error, and potentially fail to block or restrict a potentially nefarious user. |
| CVE-2020-10534 | CRITICAL | 9.8 | Mar 12, 2020 | In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges. This is related to the case in which an IP address is contained in two ranges, one of which is locally disabled. |
| CVE-2021-46147 | HIGH | 8.8 | Jan 10, 2022 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. MassEditRegex allows CSRF. |
| CVE-2021-36132 | HIGH | 8.8 | Jul 2, 2021 | An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of the $wgFileImporterRequiredRight variable, it might not validate all appropriate user rights, thus allowing a user with insufficient rights to perform operations (specifically file uploads) that they should not be allowed to perform. |
| CVE-2020-29004 | HIGH | 8.8 | Jan 29, 2021 | The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack. |
| CVE-2020-35626 | HIGH | 8.8 | Dec 21, 2020 | An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php. |
| CVE-2020-35625 | HIGH | 8.8 | Dec 21, 2020 | An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages within the Widgets namespace could call any static function within any class (defined within PHP or MediaWiki) via a crafted HTML comment, related to a Smarty template. For example, a person in the Widget Editors group could use \MediaWiki\Shell\Shell::command within a comment. |
| CVE-2024-40597 | HIGH | 7.5 | Jul 7, 2024 | An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information for log events. (The log_deleted attribute is not respected.) |
| CVE-2024-34506 | HIGH | 7.5 | May 5, 2024 | An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands of subpages, then the page will exceed the maximum request time, leading to a denial of service. |
| CVE-2023-45371 | HIGH | 7.5 | Oct 9, 2023 | An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is no rate limit for merging items. |
Showing the 20 most severe of 181 known CVEs.
Get Third Party Support