Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-29208

Опубликовано: 15 апр. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

XWiki Commons are technical libraries common to several other top level XWiki projects. Rights added to a document are not taken into account for viewing it once it's deleted. Note that this vulnerability only impact deleted documents that where containing view rights: the view rights provided on a space of a deleted document are properly checked. The problem has been patched in XWiki 14.10 by checking the rights of current user: only admin and deleter of the document are allowed to view it.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
Версия от 1.1 (включая) до 13.10.11 (исключая)
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
Версия от 14.4.0 (включая) до 14.4.7 (исключая)
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
Версия от 14.5 (включая) до 14.10 (исключая)

EPSS

Процентиль: 45%
0.00226
Низкий

7.5 High

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 7.5
github
почти 3 года назад

org.xwiki.platform:xwiki-platform-oldcore vulnerable to data leak through deleted documents

EPSS

Процентиль: 45%
0.00226
Низкий

7.5 High

CVSS3

Дефекты

CWE-668