CVE-2025-49594

Source
https://cve.org/CVERecord?id=CVE-2025-49594
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49594.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-49594
Aliases
Published
2025-10-06T14:48:43.609Z
Modified
2026-04-02T12:51:26.190318Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
XWiki OIDC Authenticator vulnerable to creation of token for any user with just `view` right
Details

XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Starting in version 2.17.1 and prior to version 2.18.2, anyone with VIEW access to a user profile can create a token for that user. If that XWiki instance is configured to allow token authentication, it allows authentication with any user (since users are very commonly viewable, at least to other registered users). Version 2.18.2 contains a patch. As a workaround, disable token access.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49594.json",
    "cwe_ids": [
        "CWE-285"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/xwiki-contrib/oidc

Affected ranges

Type
GIT
Repo
https://github.com/xwiki-contrib/oidc
Events

Affected versions

oidc-2.*
oidc-2.17.1
oidc-2.17.2
oidc-2.17.3
oidc-2.17.4
oidc-2.18.0
oidc-2.18.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49594.json"