CVE-2021-31552
NixOS vulnerability analysis and mitigation

Overview

An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules related to blocking accounts after account creation. Such rules would allow for user accounts to be created while blocking only the IP address used to create an account (and not the user account itself). Such rules could also be used by a nefarious, unprivileged user to catalog and enumerate any number of IP addresses related to these account creations (NVD, Phabricator).

Technical details

The vulnerability exists in the AbuseFilter extension's account creation blocking functionality. When a filter with 'block' action is triggered during account creation, it only blocks the IP address but fails to block the actual account being created. This implementation flaw allows the account to be created successfully while only blocking the originating IP address. The vulnerability has a CVSS v3.1 Base Score of 5.4 (MEDIUM) with vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N (NVD).

Impact

The vulnerability has two main impacts: 1) It allows accounts to be created even when they should be blocked by abuse filters, potentially leading to SUL fragmentation and creation of inappropriate usernames. 2) It enables unprivileged users to collect IP addresses of account creators through misconfigured or malicious edit filters, representing a privacy concern (Phabricator).

Mitigation and workarounds

The issue was fixed in MediaWiki versions 1.35.2 and later by modifying how AbuseFilter handles blocking during account creation. The fix ensures that both the account and the IP address are properly blocked when an abuse filter is triggered (NVD, Phabricator).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-48606HIGH7.8
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48639HIGH7.3
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48625HIGH7
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48608MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48569MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management