Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS01Y2Y4LXZycjgtOGhqbc4AAx7N

XWiki Platform packages Expose Sensitive Information to an Unauthorized Actor

Impact

Users can deduce the content of the password fields by repeated call to LiveTableResults and WikisLiveTableResultsMacros.

Patches

The issue is applied on versions 14.7-rc-1, 13.4.4, and 13.10.9.

Workarounds

The issue can be fixed by upgrading to versions 14.7-rc-1, 13.4.4, and 13.10.9 and higher, or in version >= 3.2M3 by applying the patch manually on LiveTableResults and WikisLiveTableResultsMacros.

References

For more information

If you have any questions or comments about this advisory:

Permalink: https://github.com/advisories/GHSA-5cf8-vrr8-8hjm
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01Y2Y4LXZycjgtOGhqbc4AAx7N
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 1 year ago
Updated: over 1 year ago


CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Identifiers: GHSA-5cf8-vrr8-8hjm, CVE-2023-26476
References: Repository: https://github.com/xwiki/xwiki-platform
Blast Radius: 1.0

Affected Packages

maven:org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
Affected Version Ranges: >= 14.0.0, < 14.7-rc-1, >= 13.5.0, < 13.10.9, >= 3.2-m3, < 13.4.4
Fixed in: 14.7-rc-1, 13.10.9, 13.4.4
maven:org.xwiki.platform:xwiki-platform-livetable-ui
Affected Version Ranges: >= 14.0.0, < 14.7-rc-1, >= 13.5.0, < 13.10.9, >= 3.2-m3, < 13.4.4
Fixed in: 14.7-rc-1, 13.10.9, 13.4.4