Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cwq6-mjmx-47p6

Опубликовано: 12 дек. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

XWiki's scheduler in subwiki allows scheduling operations for any main wiki user

Impact

Any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki without any special right, view the document Scheduler.WebHome in a subwiki. Then, click on any operation (e.g., Trigger) on any job. If the operation is successful, then the instance is vulnerable.

Patches

This has been patched in XWiki 15.10.9 and 16.3.0.

Workarounds

If you have subwikis where the Job Scheduler is enabled, you can edit the objects on Scheduler.WebPreferences to match https://github.com/xwiki/xwiki-platform/commit/54bcc5a7a2e440cc591b91eece9c13dc0c487331#diff-8e274bd0065e319a34090339de6dfe56193144d15fd71c52c1be7272254728b4.

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-scheduler-ui

maven
Затронутые версииВерсия исправления

>= 1.2-milestone-2, < 15.10.9

15.10.9

Наименование

org.xwiki.platform:xwiki-platform-scheduler-ui

maven
Затронутые версииВерсия исправления

>= 16.0.0-rc-1, < 16.3.0

16.3.0

EPSS

Процентиль: 60%
0.00392
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.4
nvd
около 1 года назад

XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki without any special right, view the document `Scheduler.WebHome` in a subwiki. Then, click on any operation (*e.g.,* Trigger) on any job. If the operation is successful, then the instance is vulnerable. This has been patched in XWiki 15.10.9 and 16.3.0. As a workaround, those who have subwikis where the Job Scheduler is enabled can edit the objects on `Scheduler.WebPreferences` to match the patch.

EPSS

Процентиль: 60%
0.00392
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862