Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gf7x-2j2x-7f73

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Missing authorization in xwiki-platform

Impact

Any user with edit right can copy the content of a page it does not have access to by using it as template of a new page.

Patches

It has been patched in XWiki 13.2CR1 and 12.10.6

Workarounds

There is no workaround beside patching.

References

https://jira.xwiki.org/browse/XWIKI-18430

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-oldcore

maven
Затронутые версииВерсия исправления

< 12.10.6

12.10.6

Наименование

org.xwiki.platform:xwiki-platform-oldcore

maven
Затронутые версииВерсия исправления

>= 13.0, <= 13.1

13.2-rc-1

EPSS

Процентиль: 20%
0.00066
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit right can copy the content of a page it does not have access to by using it as template of a new page. This issue has been patched in XWiki 13.2CR1 and 12.10.6. Users are advised to update. There are no known workarounds for this issue.

EPSS

Процентиль: 20%
0.00066
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862