Description
An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. It did not validate the oarc_version (aka oauth_registered_consumer.oarc_version) parameter's length.
Remediation
References
Related Vulnerabilities
WordPress Plugin Collapse-O-Matic Cross-Site Scripting (1.8.2)
WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.14)
Drupal Core 8.8.x Arbitrary File Overwrite (8.8.0 - 8.8.12)
WordPress Plugin Gallery for Social Photo Cross-Site Request Forgery (1.0.0.27)
Perl Use of Externally-Controlled Format String Vulnerability (CVE-2012-1151)