Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfp2-6qhm-7x43

Опубликовано: 19 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 7.9

Описание

The WikiManager REST API allows any user to create wikis

Impact

Any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. Note that this REST API is not bundled in XWiki Standard by default: it needs to be installed manually through the extension manager.

Patches

The problem has been patched in versions 15.10.15, 16.4.6 and 16.10.0 of the REST module.

Workarounds

There's no workaround other than upgrading the dependency.

References

For more information

If you have any questions or comments about this advisory:

Attribution

You can specify here who reported the issue.

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-wiki-rest-default

maven
Затронутые версииВерсия исправления

>= 5.4-rc-1, < 15.10.15

15.10.15

Наименование

org.xwiki.platform:xwiki-platform-wiki-rest-default

maven
Затронутые версииВерсия исправления

>= 16.0.0-rc-1, < 16.4.6

16.4.6

Наименование

org.xwiki.platform:xwiki-platform-wiki-rest-default

maven
Затронутые версииВерсия исправления

>= 16.5.0-rc-1, < 16.10.0

16.10.0

EPSS

Процентиль: 45%
0.00555
Низкий

7.9 High

CVSS4

Дефекты

CWE-285
CWE-862

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. Note that this REST API is not bundled in XWiki Standard by default: it needs to be installed manually through the extension manager. The problem has been patched in versions 15.10.15, 16.4.6 and 16.10.0 of the REST module.

CVSS3: 7.2
fstec
больше 1 года назад

Уязвимость компонента org.xwiki.platform:xwiki-platform-wiki-rest-default платформы создания совместных веб-приложений XWiki Platform, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 45%
0.00555
Низкий

7.9 High

CVSS4

Дефекты

CWE-285
CWE-862