Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-22q5-9phm-744v

Опубликовано: 19 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 8.7

Описание

XWiki allows unregistered users to access private pages information through REST endpoint

Impact

Protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesn't have view rights on them. It's particularly true if the entire wiki is protected with "Prevent unregistered user to view pages": the endpoint would still list the pages of the wiki (actually it only impacts the main wiki due to XWIKI-22639).

Patches

The problem has been patched in XWiki 15.10.14, 16.4.6, 16.10.0RC1. In those versions the endpoint can still be requested but the result is filtered out based on pages rights.

Workarounds

There's no workaround except upgrading or applying manually the changes of the commits (see references) in xwiki-platform-rest-server and recompiling / rebuilding it.

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-rest-server

maven
Затронутые версииВерсия исправления

>= 1.9M1, < 15.10.14

15.10.14

Наименование

org.xwiki.platform:xwiki-platform-rest-server

maven
Затронутые версииВерсия исправления

>= 16.0.0-rc-1, < 16.4.6

16.4.6

Наименование

org.xwiki.platform:xwiki-platform-rest-server

maven
Затронутые версииВерсия исправления

>= 16.5.0-rc-1, < 16.10.0-rc-1

16.10.0-rc-1

EPSS

Процентиль: 57%
0.00357
Низкий

8.7 High

CVSS4

Дефекты

CWE-402

Связанные уязвимости

CVSS3: 5.3
nvd
8 месяцев назад

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesn't have view rights on them. It's particularly true if the entire wiki is protected with "Prevent unregistered user to view pages": the endpoint would still list the pages of the wiki, though only for the main wiki. The problem has been patched in XWiki 15.10.14, 16.4.6, 16.10.0RC1. In those versions the endpoint can still be requested but the result is filtered out based on pages rights.

CVSS3: 7.5
fstec
8 месяцев назад

Уязвимость компонента org.xwiki.platform:xwiki-platform-rest-server платформы создания совместных веб-приложений XWiki Platform, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 57%
0.00357
Низкий

8.7 High

CVSS4

Дефекты

CWE-402