Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1qam01LTV2OXYtN2h4Ms4AAyuv

org.xwiki.platform:xwiki-platform-security-authentication-default XSS with authenticate endpoints

Impact

It was possible to inject some code using the URL of authenticate endpoints, e.g.:

https://hostname/xwiki/authenticate/wiki/xwiki%22onload=%22alert(origin)%22/resetpassword

This vulnerability was present in recent versions of XWiki:

Patches

This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.

Workarounds

There is no easy workaround except to upgrade.

References

For more information

If you have any questions or comments about this advisory:

Permalink: https://github.com/advisories/GHSA-jjm5-5v9v-7hx2
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qam01LTV2OXYtN2h4Ms4AAyuv
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 1 year ago
Updated: about 1 year ago


CVSS Score: 5.4
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Identifiers: GHSA-jjm5-5v9v-7hx2, CVE-2023-29506
References: Repository: https://github.com/xwiki/xwiki-platform
Blast Radius: 1.0

Affected Packages

maven:org.xwiki.platform:xwiki-platform-security-authentication-default
Affected Version Ranges: >= 14.6, < 14.10, >= 14.4.3, < 14.4.7, >= 13.10.8, < 13.10.11
Fixed in: 14.10, 14.4.7, 13.10.11