Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
| Software | From | Fixed in |
|---|---|---|
| mediawiki / mediawiki | 1.27.5 | 1.27.5.x |
| mediawiki / mediawiki | 1.29.3 | 1.29.3.x |
| mediawiki / mediawiki | 1.30.1 | 1.30.1.x |
| mediawiki / mediawiki | 1.31.0 | 1.31.1 |
| debian / debian_linux | 9.0 | 9.0.x |