Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jjm5-5v9v-7hx2

Опубликовано: 12 апр. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

org.xwiki.platform:xwiki-platform-security-authentication-default XSS with authenticate endpoints

Impact

It was possible to inject some code using the URL of authenticate endpoints, e.g.:

https://hostname/xwiki/authenticate/wiki/xwiki%22onload=%22alert(origin)%22/resetpassword

This vulnerability was present in recent versions of XWiki:

  • 13.10.8+
  • 14.4.3+
  • 14.6+

Patches

This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.

Workarounds

There is no easy workaround except to upgrade.

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-security-authentication-default

maven
Затронутые версииВерсия исправления

>= 13.10.8, < 13.10.11

13.10.11

Наименование

org.xwiki.platform:xwiki-platform-security-authentication-default

maven
Затронутые версииВерсия исправления

>= 14.4.3, < 14.4.7

14.4.7

Наименование

org.xwiki.platform:xwiki-platform-security-authentication-default

maven
Затронутые версииВерсия исправления

>= 14.6, < 14.10

14.10

EPSS

Процентиль: 97%
0.41315
Средний

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 3 года назад

XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.

EPSS

Процентиль: 97%
0.41315
Средний

5.4 Medium

CVSS3

Дефекты

CWE-79