Описание
XWiki Commons are technical libraries common to several other top level XWiki projects. Rights added to a document are not taken into account for viewing it once it's deleted. Note that this vulnerability only impact deleted documents that where containing view rights: the view rights provided on a space of a deleted document are properly checked. The problem has been patched in XWiki 14.10 by checking the rights of current user: only admin and deleter of the document are allowed to view it.
Ссылки
- Patch
- ExploitPatchVendor Advisory
- ExploitIssue Tracking
- Patch
- ExploitPatchVendor Advisory
- ExploitIssue Tracking
Уязвимые конфигурации
Конфигурация 1Версия от 1.1 (включая) до 13.10.11 (исключая)Версия от 14.4.0 (включая) до 14.4.7 (исключая)Версия от 14.5 (включая) до 14.10 (исключая)
Одно из
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00226
Низкий
7.5 High
CVSS3
Дефекты
CWE-668
Связанные уязвимости
CVSS3: 7.5
github
почти 3 года назад
org.xwiki.platform:xwiki-platform-oldcore vulnerable to data leak through deleted documents
EPSS
Процентиль: 45%
0.00226
Низкий
7.5 High
CVSS3
Дефекты
CWE-668