Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-xh35-w7wg-95v3: XWiki has no right protection on rollback action

Impact

The rollback action is missing a right protection: it means that a user can rollback to a previous version of the page to gain rights they don’t have anymore. This vulnerability impacts all version of XWiki since rollback action is available.

Patches

The problem has been patched in XWiki 14.10.16, 15.5.3 and 15.8-rc-1 by ensuring that the rights are checked before performing the rollback.

Workarounds

There’s no workaround for this vulnerability, except paying attention to delete old versions of documents that could allow users to gain more rights.

References

For more information

If you have any questions or comments about this advisory:

ghsa
#vulnerability#git#java#jira#maven

Package

maven org.xwiki.platform:xwiki-platform (Maven)

Affected versions

>= 15.0-rc-1, < 15.5.3

>= 15.6-rc-1, < 15.8-rc-1

Patched versions

15.5.3

15.8-rc-1

maven org.xwiki.platform:xwiki-platform-oldcore (Maven)

>= 1.0, < 14.10.17

14.10.17

Description

Impact

The rollback action is missing a right protection: it means that a user can rollback to a previous version of the page to gain rights they don’t have anymore.
This vulnerability impacts all version of XWiki since rollback action is available.

Patches

The problem has been patched in XWiki 14.10.16, 15.5.3 and 15.8-rc-1 by ensuring that the rights are checked before performing the rollback.

Workarounds

There’s no workaround for this vulnerability, except paying attention to delete old versions of documents that could allow users to gain more rights.

References

  • JIRA ticket: https://jira.xwiki.org/browse/XWIKI-21257
  • Commit: 4de72875ca49602796165412741033bfdbf1e680

For more information

If you have any questions or comments about this advisory:

  • Open an issue in Jira XWiki.org
  • Email us at Security Mailing List

References

  • GHSA-xh35-w7wg-95v3
  • xwiki/xwiki-platform@1f3220f
  • xwiki/xwiki-platform@4de7287
  • xwiki/xwiki-platform@4fa7f30
  • https://jira.xwiki.org/browse/XWIKI-21257

surli published to xwiki/xwiki-platform

Jan 8, 2024

Published to the GitHub Advisory Database

Jan 8, 2024

Reviewed

Jan 8, 2024

Last updated

Jan 8, 2024

ghsa: Latest News

GHSA-486g-47cc-8wxf: aiocpa contains credential harvesting code