Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfp2-6qhm-7x43

Опубликовано: 19 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 7.9

Описание

The WikiManager REST API allows any user to create wikis

Impact

Any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. Note that this REST API is not bundled in XWiki Standard by default: it needs to be installed manually through the extension manager.

Patches

The problem has been patched in versions 15.10.15, 16.4.6 and 16.10.0 of the REST module.

Workarounds

There's no workaround other than upgrading the dependency.

References

For more information

If you have any questions or comments about this advisory:

Attribution

You can specify here who reported the issue.

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-wiki-rest-default

maven
Затронутые версииВерсия исправления

>= 5.4-rc-1, < 15.10.15

15.10.15

Наименование

org.xwiki.platform:xwiki-platform-wiki-rest-default

maven
Затронутые версииВерсия исправления

>= 16.0.0-rc-1, < 16.4.6

16.4.6

Наименование

org.xwiki.platform:xwiki-platform-wiki-rest-default

maven
Затронутые версииВерсия исправления

>= 16.5.0-rc-1, < 16.10.0

16.10.0

EPSS

Процентиль: 81%
0.01497
Низкий

7.9 High

CVSS4

Дефекты

CWE-285
CWE-862

Связанные уязвимости

CVSS3: 9.8
nvd
11 месяцев назад

XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. Note that this REST API is not bundled in XWiki Standard by default: it needs to be installed manually through the extension manager. The problem has been patched in versions 15.10.15, 16.4.6 and 16.10.0 of the REST module.

CVSS3: 7.2
fstec
11 месяцев назад

Уязвимость компонента org.xwiki.platform:xwiki-platform-wiki-rest-default платформы создания совместных веб-приложений XWiki Platform, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 81%
0.01497
Низкий

7.9 High

CVSS4

Дефекты

CWE-285
CWE-862