Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qpp2-2mcp-2wm5

Опубликовано: 08 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Unauthenticated user can list hidden document from multiple velocity templates in XWiki

Impact

A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents.

Patches

The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1.

Workarounds

There is no known workaround for this problem.

References

https://jira.xwiki.org/browse/XWIKI-16544

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-web

maven
Затронутые версииВерсия исправления

< 12.10.11

12.10.11

Наименование

org.xwiki.platform:xwiki-platform-web

maven
Затронутые версииВерсия исправления

>= 13.0.0, < 13.4.4

13.4.4

Наименование

org.xwiki.platform:xwiki-platform-web

maven
Затронутые версииВерсия исправления

>= 13.5.0, < 13.9

13.9

EPSS

Процентиль: 32%
0.00119
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-306
CWE-359

Связанные уязвимости

CVSS3: 5.3
nvd
почти 4 года назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents. The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1. There is no known workaround for this problem.

EPSS

Процентиль: 32%
0.00119
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-306
CWE-359