Versions mentioned in the description apply to the upstream
Remediation section below for
Debian:9 relevant versions.
An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently have permissions for.
mediawiki to version 1:1.27.7-1~deb9u8 or higher.