Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8692-g6g9-gm5p

Опубликовано: 03 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.6

Описание

xwiki contains Exposed Dangerous Method or Function

Impact

org.xwiki.store.script.TemporaryAttachmentsScriptService#uploadTemporaryAttachment is returning an instance of com.xpn.xwiki.doc.XWikiAttachment. This class is not supported to be exposed to users without the programing right. com.xpn.xwiki.api.Attachment should be used instead and takes case of checking the user's rights before performing dangerous operations.

Patches

This has been patched in the version 14.9-rc-1 and 14.4.6.

Workarounds

There's no workaround for this issue.

References

https://jira.xwiki.org/browse/XWIKI-20180

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-store-filesystem-oldcore

maven
Затронутые версииВерсия исправления

>= 14.3-rc-1, < 14.4.6

14.4.6

Наименование

org.xwiki.platform:xwiki-platform-store-filesystem-oldcore

maven
Затронутые версииВерсия исправления

>= 14.5, < 14.9-rc-1

14.9-rc-1

EPSS

Процентиль: 60%
0.0039
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-749

Связанные уязвимости

CVSS3: 6.6
nvd
почти 3 года назад

XWiki Platform is a generic wiki platform. Starting in version 14.3-rc-1, `org.xwiki.store.script.TemporaryAttachmentsScriptService#uploadTemporaryAttachment` returns an instance of `com.xpn.xwiki.doc.XWikiAttachment`. This class is not supported to be exposed to users without the `programing` right. `com.xpn.xwiki.api.Attachment` should be used instead and takes case of checking the user's rights before performing dangerous operations. This has been patched in versions 14.9-rc-1 and 14.4.6. There are no known workarounds for this issue.

EPSS

Процентиль: 60%
0.0039
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-749