MediaWiki 1.39.3
31 March 2023
MediaWiki version 1.39.3 is now available (security release).
Upgrading to MediaWiki 1.39.3
MediaWiki 1.39.3 can be upgraded to (or installed) using any of Installatron's products. Use Installatron's optional Automatic Update feature to automatically apply MediaWiki updates as new versions are released, or use Installatron's Clone feature to duplicate an existing MediaWiki install to test the 1.39.3 upgrade prior to applying it live. Get started managing your MediaWiki installations with Installatron
What's New in MediaWiki 1.39.3
This is a security and maintenance release of the MediaWiki 1.39 branch.
Security
- (T285159, CVE-2023-PENDING) SECURITY: Do not apply autoblocks to untrusted XFF headers.
Bug Fixes and Changes
- Localisation updates.
- (T225218) LinksUpdate: Use DB key for category links table.
- GlobalFunctions: Remove check for MEDIAWIKI constant.
- (T329484) API: Fix query+allimages user parameter description.
- (T330529) SpecialEditTags: Set default of '' for wpReason.
- (T330382) postgres: Make the upgrade ignore dropping indexes that might not exist.
- (T330526) htmlform: Handle null from HTMLFormField::getDefault in multiselects.
- (T291753) rdbms: escape backslashes in makeConnectionString for PostgreSQL.
- (T325529) Fix total breakage of wgCanonicalServer fallback.
- (T318103) mediawiki.storage: Disable async GC during integration test.
- (T332461, T332397) TempFSFile: Keep the WeakMap alive.
- (T332902) page: fix InvalidArgumentException in SQLPlatform::makeList.