Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7f2f-pcv3-j2r7

Опубликовано: 20 июн. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

XWiki Platform's tags on non-viewable pages can be revealed to users

Impact

Tags from pages not viewable to the current user are leaked by the tags API. This information can also be exploited to infer the document reference of non-viewable pages.

Patches

This vulnerability has been patched in XWiki 14.4.8, 14.10.4, and 15.0 RC1.

Workarounds

There is no workaround apart from upgrading to a fixed version.

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-tag-api

maven
Затронутые версииВерсия исправления

>= 5.0-milestone-1, < 14.4.8

14.4.8

Наименование

org.xwiki.platform:xwiki-platform-tag-api

maven
Затронутые версииВерсия исправления

>= 14.5, < 14.10.4

14.10.4

EPSS

Процентиль: 41%
0.0019
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
nvd
больше 2 лет назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.0-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, tags from pages not viewable to the current user are leaked by the tags API. This information can also be exploited to infer the document reference of non-viewable pages. This vulnerability has been patched in XWiki 14.4.8, 14.10.4, and 15.0-rc-1.

EPSS

Процентиль: 41%
0.0019
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200