Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-24820: Unauthenticated user can list hidden document from multiple velocity templates

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents. The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1. There is no known workaround for this problem.

CVE
#web#java#auth#jira#maven

Package

maven org.xwiki.platform:xwiki-platform-web (Maven)

Affected versions

< 8.4.5, < 10.11.8, < 11.3.1, < 13.6-rc-1

Patched versions

12.10.11, 13.4.4, 13.9-rc-1

Description

Impact

A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents.

Patches

The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1.

Workarounds

There is no known workaround for this problem.

References

https://jira.xwiki.org/browse/XWIKI-16544

For more information

If you have any questions or comments about this advisory:

  • Open an issue in Jira XWiki
  • Email us at our security mailing list

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907