MediaWiki 1.24.x before 1.24.2, when using PBKDF2 for password hashing, allows remote attackers to cause a denial of service (CPU consumption) via a long password.
| Software | From | Fixed in |
|---|---|---|
| mediawiki / mediawiki | 1.24.0 | 1.24.0.x |
| mediawiki / mediawiki | 1.24.1 | 1.24.1.x |