Логотип exploitDog
bind:CVE-2023-50719
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-50719

Количество 3

Количество 3

nvd логотип

CVE-2023-50719

около 2 лет назад

XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respective user profiles. By default, all user profiles are public. This vulnerability also affects any configurations used by extensions that contain passwords like API keys that are viewable for the attacker. Normally, such passwords aren't accessible but this vulnerability would disclose them as plain text. This has been patched in XWiki 14.10.15, 15.5.2 and 15.7RC1. There are no known workarounds for this vulnerability.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-p6cp-6r35-32mh

около 2 лет назад

Solr search discloses password hashes of all users

CVSS3: 7.5
EPSS: Средний
fstec логотип

BDU:2024-01248

около 2 лет назад

Уязвимость платформы создания совместных веб-приложений XWiki Platform XWiki , связанная с незашифрованным хранением критичной информации, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-50719

XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respective user profiles. By default, all user profiles are public. This vulnerability also affects any configurations used by extensions that contain passwords like API keys that are viewable for the attacker. Normally, such passwords aren't accessible but this vulnerability would disclose them as plain text. This has been patched in XWiki 14.10.15, 15.5.2 and 15.7RC1. There are no known workarounds for this vulnerability.

CVSS3: 7.5
46%
Средний
около 2 лет назад
github логотип
GHSA-p6cp-6r35-32mh

Solr search discloses password hashes of all users

CVSS3: 7.5
46%
Средний
около 2 лет назад
fstec логотип
BDU:2024-01248

Уязвимость платформы создания совместных веб-приложений XWiki Platform XWiki , связанная с незашифрованным хранением критичной информации, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
46%
Средний
около 2 лет назад

Уязвимостей на страницу