Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ghcq-472w-vf4h

Опубликовано: 08 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Incorrect Use of Privileged APIs in org.xwiki.platform.skin.skinx

Impact

Simple users can create global SSX/JSX without specific rights: in theory only users with Programming Rights should be allowed to create SSX or JSX that are executed everywhere on a wiki. But a bug allow anyone with edit rights to actually create those.

Patches

This issue has been patched in XWiki 13.10-rc-1, 12.10.11 and 13.4.6.

Workarounds

There's no easy workaround for this issue, administrators should upgrade their wiki.

References

https://jira.xwiki.org/browse/XWIKI-19155

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-skin-skinx

maven
Затронутые версииВерсия исправления

>= 13.5.0, < 13.10

13.10

Наименование

org.xwiki.platform:xwiki-platform-skin-skinx

maven
Затронутые версииВерсия исправления

< 12.10.11

12.10.11

Наименование

org.xwiki.platform:xwiki-platform-skin-skinx

maven
Затронутые версииВерсия исправления

>= 13.0.0, < 13.4.6

13.4.6

EPSS

Процентиль: 72%
0.00699
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-648

Связанные уязвимости

CVSS3: 6.8
nvd
почти 4 года назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Simple users can create global SSX/JSX without specific rights: in theory only users with Programming Rights should be allowed to create SSX or JSX that are executed everywhere on a wiki. But a bug allow anyone with edit rights to actually create those. This issue has been patched in XWiki 13.10-rc-1, 12.10.11 and 13.4.6. There's no easy workaround for this issue, administrators should upgrade their wiki.

EPSS

Процентиль: 72%
0.00699
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-648