Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS12cHg0LTdyZnAtaDU0Nc4AAx7M

Unprivileged XWiki Platform users can make arbitrary select queries using DatabaseListProperty and suggest.vm

Impact

Any user with edit right can execute arbitrary database select and access data stored in the database.

To reproduce:

Patches

The problem has been patched on XWiki 13.10.11, 14.4.7, and 14.10.

Workarounds

There is no workaround for this vulnerability other than upgrading.

References

https://jira.xwiki.org/browse/XWIKI-19523

For more information

If you have any questions or comments about this advisory:

Permalink: https://github.com/advisories/GHSA-vpx4-7rfp-h545
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12cHg0LTdyZnAtaDU0Nc4AAx7M
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 1 year ago
Updated: about 1 year ago


CVSS Score: 6.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Identifiers: GHSA-vpx4-7rfp-h545, CVE-2023-26473
References: Repository: https://github.com/xwiki/xwiki-platform
Blast Radius: 1.0

Affected Packages

maven:org.xwiki.platform:xwiki-platform-web
Affected Version Ranges: >= 14.5, < 14.10, >= 14.0, < 14.4.7, >= 1.3-rc-1, < 13.10.11
Fixed in: 14.10, 14.4.7, 13.10.11