Описание
XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activated. The issue has been patched in XWiki 14.4.8, 14.10.6, and 15.1. There is no known workaround.
Ссылки
- PatchVendor Advisory
- Vendor Advisory
- Issue TrackingVendor Advisory
- PatchVendor Advisory
- Vendor Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 7.4 (включая) до 14.4.8 (исключая)Версия от 14.10 (включая) до 14.10.6 (исключая)
Одно из
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:7.3:milestone1:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:15.0:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:15.0:rc1:*:*:*:*:*:*
EPSS
Процентиль: 43%
0.00208
Низкий
7.5 High
CVSS3
Дефекты
CWE-359
CWE-668
Связанные уязвимости
CVSS3: 7.5
github
больше 2 лет назад
XWiki Platform may show email addresses in clear in REST results
EPSS
Процентиль: 43%
0.00208
Низкий
7.5 High
CVSS3
Дефекты
CWE-359
CWE-668