Логотип exploitDog
bind:CVE-2022-31167
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-31167

Количество 2

Количество 2

nvd логотип

CVE-2022-31167

больше 3 лет назад

XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.10.11, 13.10.1, and 13.4.6, a bug in the security cache stores rules associated to document Page1.Page2 and space Page1.Page2 in the same cache entry. That means that it's possible to overwrite the rights of a space or a document by creating the page of the space with the same name and checking the right of the new one first so that they end up in the security cache and are used for the other too. The problem has been patched in XWiki 12.10.11, 13.10.1, and 13.4.6. There are no known workarounds.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-gg53-wf5x-r3r6

больше 3 лет назад

XWiki Platform Security Parent POM vulnerable to overwriting of security rules of a page with a final page having the same reference

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-31167

XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.10.11, 13.10.1, and 13.4.6, a bug in the security cache stores rules associated to document Page1.Page2 and space Page1.Page2 in the same cache entry. That means that it's possible to overwrite the rights of a space or a document by creating the page of the space with the same name and checking the right of the new one first so that they end up in the security cache and are used for the other too. The problem has been patched in XWiki 12.10.11, 13.10.1, and 13.4.6. There are no known workarounds.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-gg53-wf5x-r3r6

XWiki Platform Security Parent POM vulnerable to overwriting of security rules of a page with a final page having the same reference

CVSS3: 7.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу