Page MenuHomeMiraheze
Feed Advanced Search

Wed, Mar 27

OrangeStar changed the visibility for T11999: Leak of suppressed wiki requests via Special:RequestWikiQueue outside of Meta.
Wed, Mar 27, 20:05 · MediaWiki (SRE), OrangeStar, CreateWiki, Security
OrangeStar closed T11999: Leak of suppressed wiki requests via Special:RequestWikiQueue outside of Meta as Resolved.
Wed, Mar 27, 19:47 · MediaWiki (SRE), OrangeStar, CreateWiki, Security
OrangeStar claimed T11999: Leak of suppressed wiki requests via Special:RequestWikiQueue outside of Meta.
Wed, Mar 27, 19:04 · MediaWiki (SRE), OrangeStar, CreateWiki, Security
OrangeStar updated the task description for T11999: Leak of suppressed wiki requests via Special:RequestWikiQueue outside of Meta.
Wed, Mar 27, 17:16 · MediaWiki (SRE), OrangeStar, CreateWiki, Security
OrangeStar renamed T11999: Leak of suppressed wiki requests via Special:RequestWikiQueue outside of Meta from Leak of suppressed wiki requests via Special:RequestWikiQueue on outside of Meta to Leak of suppressed wiki requests via Special:RequestWikiQueue outside of Meta.
Wed, Mar 27, 16:55 · MediaWiki (SRE), OrangeStar, CreateWiki, Security
OrangeStar renamed T11999: Leak of suppressed wiki requests via Special:RequestWikiQueue outside of Meta from Leak of suppressed wiki requests via Special:RequestWikiQueue on non-Meta wikis to Leak of suppressed wiki requests via Special:RequestWikiQueue on outside of Meta.
Wed, Mar 27, 15:36 · MediaWiki (SRE), OrangeStar, CreateWiki, Security
OrangeStar added a comment to T11999: Leak of suppressed wiki requests via Special:RequestWikiQueue outside of Meta.

https://github.com/miraheze/CreateWiki/security/advisories/GHSA-4rcf-3cj2-46mq

Wed, Mar 27, 14:57 · MediaWiki (SRE), OrangeStar, CreateWiki, Security
OrangeStar created T11999: Leak of suppressed wiki requests via Special:RequestWikiQueue outside of Meta.
Wed, Mar 27, 14:03 · MediaWiki (SRE), OrangeStar, CreateWiki, Security

Tue, Mar 26

OrangeStar added a comment to T11993: CreateWiki suppression is broken.

GHSA published, CVE ID CVE-2024-29883 has been assigned to it.

Tue, Mar 26, 13:11 · MediaWiki (SRE), CreateWiki, OrangeStar, Security
OrangeStar added projects to T11993: CreateWiki suppression is broken: OrangeStar, CreateWiki, MediaWiki (SRE).
Tue, Mar 26, 12:24 · MediaWiki (SRE), CreateWiki, OrangeStar, Security
OrangeStar changed the visibility for T11993: CreateWiki suppression is broken.
Tue, Mar 26, 12:20 · MediaWiki (SRE), CreateWiki, OrangeStar, Security
OrangeStar closed T11993: CreateWiki suppression is broken as Resolved.
Tue, Mar 26, 11:50 · MediaWiki (SRE), CreateWiki, OrangeStar, Security
OrangeStar added a comment to T11993: CreateWiki suppression is broken.

Fixed. GHSA will be published shortly.

Tue, Mar 26, 11:50 · MediaWiki (SRE), CreateWiki, OrangeStar, Security
OrangeStar added a comment to T11993: CreateWiki suppression is broken.

https://github.com/miraheze/CreateWiki/security/advisories/GHSA-8wjf-mxjg-j8p9

Tue, Mar 26, 11:06 · MediaWiki (SRE), CreateWiki, OrangeStar, Security
OrangeStar updated the task description for T11993: CreateWiki suppression is broken.
Tue, Mar 26, 10:55 · MediaWiki (SRE), CreateWiki, OrangeStar, Security
OrangeStar created T11993: CreateWiki suppression is broken.
Tue, Mar 26, 10:54 · MediaWiki (SRE), CreateWiki, OrangeStar, Security

Sat, Mar 23

Universal_Omega lowered the priority of T10756: Graph disabled globally from Normal to Low.

Please raise back to 'normal' when this is no longer stalled.

Sat, Mar 23, 06:41 · Upstream, MediaWiki (SRE), Security

Mar 14 2024

Universal_Omega added a project to T11925: OrangeStar's LDAP account & Graylog access: Infrastructure (SRE).
Mar 14 2024, 19:32 · Infrastructure (SRE), Security
Universal_Omega changed the visibility for T11925: OrangeStar's LDAP account & Graylog access.
Mar 14 2024, 19:31 · Infrastructure (SRE), Security
Universal_Omega closed T11925: OrangeStar's LDAP account & Graylog access as Resolved.

I have removed other ldap accounts access.

Mar 14 2024, 19:30 · Infrastructure (SRE), Security

Mar 5 2024

Universal_Omega added a comment to T11925: OrangeStar's LDAP account & Graylog access.

Yes, in particular we need to investigate if it was disabled for John, Paladox, and Owen's LDAP accounts. So until then this should remain open.

Mar 5 2024, 17:50 · Infrastructure (SRE), Security
OrangeStar added a comment to T11925: OrangeStar's LDAP account & Graylog access.

Jank with the LDAP extension? Anyway, the reason this task was opened is solved now ig. However, @Universal_Omega said that other LDAP accounts should be investigated, so I guess this should be kept open or more likely, done in a separate maniphest task, since as a SWE I don't really have a need to know that information.

Mar 5 2024, 16:20 · Infrastructure (SRE), Security
MacFan4000 added a comment to T11925: OrangeStar's LDAP account & Graylog access.

I also don’t see users listed in my groups in preferences. Anyway, I’ve added you to the member group.

Mar 5 2024, 16:08 · Infrastructure (SRE), Security
MacFan4000 added a comment to T11925: OrangeStar's LDAP account & Graylog access.

Must be some sort of bug, since you should by default be a “User”.

Mar 5 2024, 16:03 · Infrastructure (SRE), Security
OrangeStar added a comment to T11925: OrangeStar's LDAP account & Graylog access.

image.png (377×1 px, 56 KB)

Mar 5 2024, 15:15 · Infrastructure (SRE), Security

Mar 4 2024

MacFan4000 updated subscribers of T11925: OrangeStar's LDAP account & Graylog access.

For the record, since you have an NDA and test151 access, I personally have no issue with you having Graylog/Ldap access, but this is an issue since offboarding seems to have not been done correctly and this is something we should review for other ldap accounts as well.

Mar 4 2024, 20:24 · Infrastructure (SRE), Security
MacFan4000 added a comment to T11925: OrangeStar's LDAP account & Graylog access.

Hmm according to https://ldapwiki.miraheze.org/wiki/Special:ListGroupRights logged in users have the read permission

Mar 4 2024, 20:17 · Infrastructure (SRE), Security
OrangeStar added a comment to T11925: OrangeStar's LDAP account & Graylog access.

Should grant me access to ldapwikiwiki then. It is a private wiki, other than view the main page, I can do literally nothing else (MacFan4000 removed the bureaucrat group from my LDAP account when I resigned iirc).

Mar 4 2024, 18:30 · Infrastructure (SRE), Security
Universal_Omega added a comment to T11925: OrangeStar's LDAP account & Graylog access.

For the record, since you have an NDA and test151 access, I personally have no issue with you having Graylog/Ldap access, but this is an issue since offboarding seems to have not been done correctly and this is something we should review for other ldap accounts as well.

Mar 4 2024, 17:15 · Infrastructure (SRE), Security
OrangeStar updated the task description for T11925: OrangeStar's LDAP account & Graylog access.
Mar 4 2024, 15:15 · Infrastructure (SRE), Security
OrangeStar created T11925: OrangeStar's LDAP account & Graylog access.
Mar 4 2024, 15:14 · Infrastructure (SRE), Security

Feb 10 2024

Universal_Omega moved T11812: Numerous confirmed XSS in ManageWiki from Backlog to Bugs on the ManageWiki board.
Feb 10 2024, 17:20 · ManageWiki, MediaWiki (SRE), Security
Universal_Omega moved T11812: Numerous confirmed XSS in ManageWiki from Backlog to Short Term on the MediaWiki (SRE) board.
Feb 10 2024, 17:19 · ManageWiki, MediaWiki (SRE), Security
Universal_Omega changed the visibility for T11812: Numerous confirmed XSS in ManageWiki.
Feb 10 2024, 17:19 · ManageWiki, MediaWiki (SRE), Security

Feb 9 2024

OrangeStar closed T11812: Numerous confirmed XSS in ManageWiki as Resolved.
Feb 9 2024, 21:31 · ManageWiki, MediaWiki (SRE), Security
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

Security advisory is now published. This task should be good for opening to the public now. For those reading this, we actually found some more XSS vectors when deploying the fixes to prod, so we actually have multiple patches in the GHSA for this one.

Feb 9 2024, 21:31 · ManageWiki, MediaWiki (SRE), Security
OrangeStar claimed T11812: Numerous confirmed XSS in ManageWiki.
Feb 9 2024, 21:16 · ManageWiki, MediaWiki (SRE), Security
OrangeStar placed T11812: Numerous confirmed XSS in ManageWiki up for grabs.

I just realized it will be better to just leave deploying the fixes to someone with access to mwtask181. Removing myself as assignee as my part is done, I think.

Feb 9 2024, 14:58 · ManageWiki, MediaWiki (SRE), Security
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

I've set confidentiality to high, since you could read private ManageWiki settings (for example, the Discord webhook for wikis using that extension) with XSS on those pages.

Feb 9 2024, 12:22 · ManageWiki, MediaWiki (SRE), Security
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

https://github.com/miraheze/ManageWiki/security/advisories/GHSA-4jr2-jhfm-2r84

Feb 9 2024, 12:00 · ManageWiki, MediaWiki (SRE), Security
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

I'm going to create a new draft GHSA, GitHub got bugged and thinks there are no changes waiting to be merged from the private fork sigh.

Feb 9 2024, 11:42 · ManageWiki, MediaWiki (SRE), Security
MacFan4000 changed the edit policy for T11814: Confirmed XSS in WikiDiscover.
Feb 9 2024, 01:26 · WikiDiscover, Security, MediaWiki (SRE)

Feb 8 2024

Universal_Omega changed the visibility for T11814: Confirmed XSS in WikiDiscover.
Feb 8 2024, 20:32 · WikiDiscover, Security, MediaWiki (SRE)
OrangeStar closed T11814: Confirmed XSS in WikiDiscover as Resolved.

https://github.com/miraheze/WikiDiscover/security/advisories/GHSA-cfcf-94jv-455f is now published and the fix is live on the latest master. I believe this is task is now good for opening to the public

Feb 8 2024, 20:27 · WikiDiscover, Security, MediaWiki (SRE)
Universal_Omega added a comment to T11814: Confirmed XSS in WikiDiscover.

Fix for this one is pretty simple. @Universal_Omega I will need you to give me permission to make security advisories on WikiDiscover as well.

Feb 8 2024, 19:59 · WikiDiscover, Security, MediaWiki (SRE)
OrangeStar claimed T11814: Confirmed XSS in WikiDiscover.

Fix for this one is pretty simple. @Universal_Omega I will need you to give me permission to make security advisories on WikiDiscover as well.

Feb 8 2024, 19:58 · WikiDiscover, Security, MediaWiki (SRE)
OrangeStar added a comment to T11814: Confirmed XSS in WikiDiscover.
<td class="TablePager_col_wiki_dbname"><a href="https://semantic-mediawiki.mirabeta.org">Semantic MediaWiki</a></td>
<td class="TablePager_col_wiki_language">English</td>
<td class="TablePager_col_wiki_closed">Open</td>
<td class="TablePager_col_wiki_private">Public</td>
<td class="TablePager_col_wiki_category">Software/Computing</td>
<td class="TablePager_col_wiki_creation">28 <script>alert('january')</script>"><script>alert('january')</script><x y="() 2022</td>
<td class="TablePager_col_wiki_description"> </td>
Feb 8 2024, 19:41 · WikiDiscover, Security, MediaWiki (SRE)
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

security advisory draft (https://github.com/miraheze/ManageWiki/security/advisories/GHSA-42fh-6pcr-3j58) is ready, all the changes have been made to the private fork if I'm not missing anything. Waiting for an SRE to review everything and give me the okay (or merge the changes themselves) so that they can double check my work and we can deploy the fixes to production as soon as possible.

Feb 8 2024, 11:14 · ManageWiki, MediaWiki (SRE), Security
Universal_Omega added a comment to T11812: Numerous confirmed XSS in ManageWiki.

Please do a security merge not a normal PR, should be fairly easy to do security with GitHub

Feb 8 2024, 10:28 · ManageWiki, MediaWiki (SRE), Security
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

I think I'm good to go to squash all of these and make a PR.

Feb 8 2024, 10:25 · ManageWiki, MediaWiki (SRE), Security
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

Feb 8 2024, 10:20 · ManageWiki, MediaWiki (SRE), Security
Universal_Omega added a comment to T11812: Numerous confirmed XSS in ManageWiki.

Adding all the messages that has an issue to wgRawHtmlMessages is a mitigation to this but it might be to complex with to many at this time.

Feb 8 2024, 10:06 · ManageWiki, MediaWiki (SRE), Security
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

@Universal_Omega You mean making the help messages in MWS.php, like https://github.com/miraheze/mw-config/blob/master/ManageWikiSettings.php#L109, interface messages? Because if so that looks like a complex rewrite. Also, all of those messages as well as managewiki-requires, managewiki-conflicts, and all the various right-* messages from core that are also XSS vectors in the permissions subpage must be added to wgRawHtmlMessages. We can do that, if you want, but after this.

Feb 8 2024, 09:51 · ManageWiki, MediaWiki (SRE), Security
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.
Feb 8 2024, 09:34 · ManageWiki, MediaWiki (SRE), Security

Feb 7 2024

Universal_Omega added a comment to T11812: Numerous confirmed XSS in ManageWiki.

I think what we should do is allow raw messages in MWS to be defined in config, and if it is, add them to $wgRawHtmlMessages, which prevents true security vulnerabilities by not only require editinterface, but also the same rights to editsitecss/js which would mean absolutely no difference from Common.js, etc...

Feb 7 2024, 21:09 · ManageWiki, MediaWiki (SRE), Security
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

Yeah there's no way my last patch is right.

Feb 7 2024, 20:07 · ManageWiki, MediaWiki (SRE), Security
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

Feb 7 2024, 19:48 · ManageWiki, MediaWiki (SRE), Security
Universal_Omega added a comment to T11812: Numerous confirmed XSS in ManageWiki.

Confirmed in Special:ManageWikiDefaultPermissions also

Feb 7 2024, 19:47 · ManageWiki, MediaWiki (SRE), Security
Universal_Omega updated subscribers of T11814: Confirmed XSS in WikiDiscover.
Feb 7 2024, 19:40 · WikiDiscover, Security, MediaWiki (SRE)
Universal_Omega created T11814: Confirmed XSS in WikiDiscover.
Feb 7 2024, 19:40 · WikiDiscover, Security, MediaWiki (SRE)
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

New patch superseding the other patch. Only thing missing is I think the XSS on the permissions subpage, which seems a bit more complex.

Feb 7 2024, 19:34 · ManageWiki, MediaWiki (SRE), Security
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

Also, just to clarify my previous message.

Feb 7 2024, 19:09 · ManageWiki, MediaWiki (SRE), Security
OrangeStar claimed T11812: Numerous confirmed XSS in ManageWiki.

I think I know what is causing this, so I'll try to get this fixed tomorrow at the latest.

Feb 7 2024, 19:06 · ManageWiki, MediaWiki (SRE), Security
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

Assuming that patch fixes that for the extensions subpage, I can more or less make a theory (the form descriptor is passed around through so many functions that it is hard to keep track).

Feb 7 2024, 18:58 · ManageWiki, MediaWiki (SRE), Security
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

Looking at meta.miraheze.org, that is indeed supposed to be the "label" (it is not actually a label HTML element)

Feb 7 2024, 18:42 · ManageWiki, MediaWiki (SRE), Security
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

https://github.com/miraheze/ManageWiki/blob/75510297a32ed8881c98212f29001d226f0a833e/includes/FormFactory/ManageWikiFormFactoryBuilder.php#L269 where required and conflicting extensions are added to the form.

Feb 7 2024, 18:29 · ManageWiki, MediaWiki (SRE), Security
OrangeStar added a comment to T11812: Numerous confirmed XSS in ManageWiki.

/extensions and /settings confirmed busted. /core doesn't give any alerts.

Feb 7 2024, 17:50 · ManageWiki, MediaWiki (SRE), Security
Universal_Omega updated the task description for T11812: Numerous confirmed XSS in ManageWiki.
Feb 7 2024, 17:49 · ManageWiki, MediaWiki (SRE), Security
Universal_Omega updated subscribers of T11812: Numerous confirmed XSS in ManageWiki.
Feb 7 2024, 17:46 · ManageWiki, MediaWiki (SRE), Security
Universal_Omega created T11812: Numerous confirmed XSS in ManageWiki.
Feb 7 2024, 17:45 · ManageWiki, MediaWiki (SRE), Security

Dec 31 2023

Redmin merged T11584: Score extension enabling into T5863: Re-enable score/Lillypond with Shellbox after security issues.
Dec 31 2023, 15:40 · Puppet, Configuration, MediaWiki (SRE), Security

Dec 20 2023

Paladox added a comment to T11549: Getting spam emails via Special:Contact.

I enabled captcha and changed the title to > 'Contact Form on ' . $wgSitename

Dec 20 2023, 13:05 · MediaWiki (SRE), MediaWiki
Legroom created T11549: Getting spam emails via Special:Contact.
Dec 20 2023, 10:16 · MediaWiki (SRE), MediaWiki

Nov 11 2023

Psephomancy added a comment to T10756: Graph disabled globally.

Looks like we can take the code between the <graph> tags and paste it into the old editor to generate PNG or SVG: https://vega.github.io/vega-editor/?mode=vega

Nov 11 2023, 14:21 · Upstream, MediaWiki (SRE), Security
Psephomancy added a comment to T10756: Graph disabled globally.

This also provides a tracking category "Category:Pages with disabled graphs" showing the pages that used to contain graphs. [...]

Nov 11 2023, 14:11 · Upstream, MediaWiki (SRE), Security
Psephomancy added a comment to T10756: Graph disabled globally.

https://en.wikipedia.org/wiki/Wikipedia:Village_pump_(technical)/Archive_205#Graph_extension_disabled_per_immediate_effect

Nov 11 2023, 14:05 · Upstream, MediaWiki (SRE), Security
RhinosF1 added a comment to T10756: Graph disabled globally.

No, it has significant security issues

Nov 11 2023, 13:50 · Upstream, MediaWiki (SRE), Security
Psephomancy added a comment to T10756: Graph disabled globally.

Is there at least some wiki where it's enabled so that we can paste the code and take screenshots and replace the broken graphs?

Nov 11 2023, 13:49 · Upstream, MediaWiki (SRE), Security
Redmin merged T11401: Graph extension not working on Electowiki into T10756: Graph disabled globally.
Nov 11 2023, 04:53 · Upstream, MediaWiki (SRE), Security

Aug 6 2023

Redmin changed the status of T10756: Graph disabled globally from Open to Stalled.
Aug 6 2023, 14:42 · Upstream, MediaWiki (SRE), Security

Jul 7 2023

Agent_Isai lowered the priority of T10756: Graph disabled globally from High to Normal.
Jul 7 2023, 20:02 · Upstream, MediaWiki (SRE), Security

Jun 30 2023

Naggieka added a comment to T11029: Bugs on saving.
Jun 30 2023, 21:18 · MediaWiki (SRE), MediaWiki
Naggieka added a comment to T11029: Bugs on saving.
Jun 30 2023, 21:17 · MediaWiki (SRE), MediaWiki
Naggieka created T11029: Bugs on saving.
Jun 30 2023, 20:58 · MediaWiki (SRE), MediaWiki

May 9 2023

Agent_Isai updated subscribers of T10756: Graph disabled globally.
May 9 2023, 16:12 · Upstream, MediaWiki (SRE), Security

Apr 26 2023

OrangeStar added a comment to T10756: Graph disabled globally.

I would also like the note that I'm going off the default description for their XSS template. It could be a different way to deliver arbitrary JS to users instead of writing JavaScript directly in the article

Apr 26 2023, 17:07 · Upstream, MediaWiki (SRE), Security
OrangeStar added a comment to T10756: Graph disabled globally.

Don't we all love responsible disclosure? We can't even investigate this.

Apr 26 2023, 17:04 · Upstream, MediaWiki (SRE), Security

Apr 22 2023

LAnonyme16 added a comment to T10763: Files loading problem.

actually I can't, because although I uploaded the files to my wiki a few months ago and didn't delete them afterwards, they seem to have completely disappeared, as if they had been deleted. When I click on the red link of one of them (for example this one: https://pauldebouvier.miraheze.org/wiki/Fichier:Phil_Argyre.png), it redirects me to an empty page (in this case, a page named "Fichier:Phil_Argyre.png", even though again I did upload a file under the title "Phil Argyre").

Apr 22 2023, 12:08 · MediaWiki (SRE), Swift
Reception123 added a comment to T10763: Files loading problem.

could you please send us a link to one of the files?

Apr 22 2023, 12:00 · MediaWiki (SRE), Swift
LAnonyme16 attached a referenced file: F2096033: Capture.PNG.
Apr 22 2023, 11:46 · MediaWiki (SRE), Swift
LAnonyme16 created T10763: Files loading problem.
Apr 22 2023, 11:43 · MediaWiki (SRE), Swift

Apr 19 2023

Reception123 added a project to T10756: Graph disabled globally: MediaWiki (SRE).
Apr 19 2023, 14:51 · Upstream, MediaWiki (SRE), Security
Agent_Isai created T10756: Graph disabled globally.
Apr 19 2023, 01:15 · Upstream, MediaWiki (SRE), Security

Feb 24 2023

John lowered the priority of T10441: Convert the private miraheze.org key from rsa to pkcs8 from High to Low.
Feb 24 2023, 21:43 · Site Reliability Engineering

Feb 7 2023

Void added a comment to T10441: Convert the private miraheze.org key from rsa to pkcs8.

Paladox and I discussed this a bit earlier, but here's the short of it:

Feb 7 2023, 23:56 · Site Reliability Engineering
Reception123 added a comment to T10441: Convert the private miraheze.org key from rsa to pkcs8.

@John does this seem fine with you?

Feb 7 2023, 19:42 · Site Reliability Engineering

Feb 5 2023

Paladox added a comment to T10441: Convert the private miraheze.org key from rsa to pkcs8.

To convert I did:

Feb 5 2023, 23:06 · Site Reliability Engineering
Paladox created T10441: Convert the private miraheze.org key from rsa to pkcs8.
Feb 5 2023, 22:59 · Site Reliability Engineering

Dec 3 2022

Reception123 merged T10041: Please restore Score extension into T5863: Re-enable score/Lillypond with Shellbox after security issues.
Dec 3 2022, 06:36 · Puppet, Configuration, MediaWiki (SRE), Security

Nov 13 2022

Owen moved T9123: Join NCSC services for enhanced support from Backlog to External on the Trust & Safety board.
Nov 13 2022, 22:04 · Trust & Safety, Site Reliability Engineering, Security