Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2gj2-vj98-j2qq

Опубликовано: 21 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.9

Описание

Missing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcore

Impact

It's possible for a user with only Script rights to enable or disable a user: this operation should be only doable for users with admin rights.

Patches

This problem has been patched in XWiki 13.10.7, 14.4.2 and 14.5RC1.

Workarounds

There is no workaround other than upgrading the wiki, but note that this only impacts users with Script rights: administrator should take care which users have such right.

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-oldcore

maven
Затронутые версииВерсия исправления

>= 11.7RC1, < 13.10.7

13.10.7

Наименование

org.xwiki.platform:xwiki-platform-oldcore

maven
Затронутые версииВерсия исправления

>= 14.0.0, < 14.4.2

14.4.2

EPSS

Процентиль: 62%
0.00434
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.9
nvd
около 3 лет назад

org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorrectly authorized user with only Script rights to enable or disable a user. This operation is meant to only be available for users with admin rights. This problem has been patched in XWiki 13.10.7, 14.4.2 and 14.5RC1.

EPSS

Процентиль: 62%
0.00434
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-862