Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1xcHAyLTJtY3AtMndtNc05dg

Unauthenticated user can list hidden document from multiple velocity templates in XWiki

Impact

A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents.

Patches

The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1.

Workarounds

There is no known workaround for this problem.

References

https://jira.xwiki.org/browse/XWIKI-16544

For more information

If you have any questions or comments about this advisory:

Permalink: https://github.com/advisories/GHSA-qpp2-2mcp-2wm5
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xcHAyLTJtY3AtMndtNc05dg
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 2 years ago
Updated: 10 months ago


CVSS Score: 5.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Identifiers: GHSA-qpp2-2mcp-2wm5, CVE-2022-24820
References: Repository: https://github.com/xwiki/xwiki-platform
Blast Radius: 1.0

Affected Packages

maven:org.xwiki.platform:xwiki-platform-web
Affected Version Ranges: >= 13.5.0, < 13.9, >= 13.0.0, < 13.4.4, < 12.10.11
Fixed in: 13.9, 13.4.4, 12.10.11