Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1ncHE1LTdwMzQtdnF4Nc4AAy58

XWiki Platform's async and display macro allow displaying and interacting with any document in restricted mode

Impact

It's possible to display any page you cannot access through the combination of the async and display macro.

Steps to reproduce:

  1. Enable comments for guests by giving guests comment rights
  2. As a guest, create a comment with content {{async}}{{display reference="Menu.WebHome" /}}{{/async}}
  3. Open the comments viewer from the menu (appends ?viewer=comments to the URL)

-> the Menu.WebHome is displayed while the expectation would be to have an error that the current user is not allowed to see it

Patches

The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.3, 14.4.8, and 13.10.11.

Workarounds

There is no known workaround.

References

https://jira.xwiki.org/browse/XWIKI-20394
https://jira.xwiki.org/browse/XRENDERING-694

For more information

If you have any questions or comments about this advisory:

Permalink: https://github.com/advisories/GHSA-gpq5-7p34-vqx5
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ncHE1LTdwMzQtdnF4Nc4AAy58
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: about 1 year ago
Updated: 6 months ago


CVSS Score: 10.0
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Identifiers: GHSA-gpq5-7p34-vqx5, CVE-2023-29526
References: Repository: https://github.com/xwiki/xwiki-platform
Blast Radius: 1.0

Affected Packages

maven:org.xwiki.platform:xwiki-platform-rendering-async-macro
Affected Version Ranges: >= 14.5, < 14.10.3, >= 14.0-rc-1, < 14.4.8, >= 10.11.1, < 13.10.11
Fixed in: 14.10.3, 14.4.8, 13.10.11
maven:org.xwiki.platform:xwiki-platform-oldcore
Affected Version Ranges: >= 14.5, < 14.10.3, >= 14.0-rc-1, < 14.4.8, >= 10.11.1, < 13.10.11
Fixed in: 14.10.3, 14.4.8, 13.10.11