Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rh28-mqj4-8x59

Опубликовано: 26 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests

Impact

XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient and with slightly modified parameters to the LiveTableResults, it is still possible to discover password hashes one bit at a time, so with 768 requests, the full password salt and hash can be retrieved of a user.

Patches

The check for password (and email properties) has been adjusted in XWiki 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17.

Workarounds

The patch can be applied manually to the wiki page XWiki.LiveTableResultsMacros.

Resources

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-livetable-ui

maven
Затронутые версииВерсия исправления

>= 6.2.1, < 16.10.17

16.10.17

Наименование

org.xwiki.platform:xwiki-platform-livetable-ui

maven
Затронутые версииВерсия исправления

>= 17.0.0-rc-1, < 17.4.9

17.4.9

Наименование

org.xwiki.platform:xwiki-platform-livetable-ui

maven
Затронутые версииВерсия исправления

>= 17.5.0-rc-1, < 17.10.3

17.10.3

EPSS

Процентиль: 30%
0.00361
Низкий

7.5 High

CVSS3

Дефекты

CWE-359

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 месяца назад

XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to the `LiveTableResults`, it is still possible to discover password hashes one bit at a time, so with 768 requests, the full password salt and hash can be retrieved of a user. The check for password (and email properties) has been adjusted in XWiki 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17. As a workaround, the patch can be applied manually to the wiki page `XWiki.LiveTableResultsMacros`.

CVSS3: 7.5
fstec
8 месяцев назад

Уязвимость компонента LiveTableResults платформы создания совместных веб-приложений XWiki Platform XWiki, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 30%
0.00361
Низкий

7.5 High

CVSS3

Дефекты

CWE-359