GHSA-4655-wh7v-3vmg

Suggest an improvement
Source
https://github.com/advisories/GHSA-4655-wh7v-3vmg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-4655-wh7v-3vmg/GHSA-4655-wh7v-3vmg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4655-wh7v-3vmg
Aliases
Published
2023-04-12T20:35:42Z
Modified
2023-11-08T04:12:18.062207Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
org.xwiki.platform:xwiki-platform-logging-ui Eval Injection vulnerability
Details

Impact

Steps to reproduce:

It is possible to trick a user with programming rights into visiting <xwiki-host>/xwiki/bin/view/XWiki/LoggingAdmin?loggeractionset=1&loggername=%7B%7Bcache%7D%7D%7B%7Bgroovy%7D%7Dnew+File%28%22%2Ftmp%2Fexploit.txt%22%29.withWriter+%7B+out+-%3E+out.println%28%22created+from+notification+filter+preferences%21%22%29%3B+%7D%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fcache%7D%7D&logger_level=TRACE where <xwiki-host> is the URL of your XWiki installation, e.g., by embedding an image with this URL in a document that is viewed by a user with programming rights.

Expected result:

No file in /tmp/exploit.txt has been created.

Actual result:

The file /tmp/exploit.txt is been created with content "created from notification filter preferences!". This demonstrates a CSRF remote code execution vulnerability that could also be used for privilege escalation or data leaks (if the XWiki installation can reach remote hosts).

Patches

The problem has been patched on XWiki 14.4.7, and 14.10.

Workarounds

The issue can be fixed manually applying this patch.

References

  • https://jira.xwiki.org/browse/XWIKI-20291
  • https://github.com/xwiki/xwiki-platform/commit/49fdfd633ddfa346c522d2fe71754dc72c9496ca

For more information

If you have any questions or comments about this advisory:

Database specific
{
    "nvd_published_at": "2023-04-17T22:15:10Z",
    "cwe_ids": [
        "CWE-352",
        "CWE-74",
        "CWE-95"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2023-04-12T20:35:42Z"
}
References

Affected packages

Maven / org.xwiki.platform:xwiki-platform-logging-ui

Package

Name
org.xwiki.platform:xwiki-platform-logging-ui
View open source insights on deps.dev
Purl
pkg:maven/org.xwiki.platform/xwiki-platform-logging-ui

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2-milestone-3
Fixed
13.10.11

Maven / org.xwiki.platform:xwiki-platform-logging-ui

Package

Name
org.xwiki.platform:xwiki-platform-logging-ui
View open source insights on deps.dev
Purl
pkg:maven/org.xwiki.platform/xwiki-platform-logging-ui

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14.0-rc-1
Fixed
14.4.7

Maven / org.xwiki.platform:xwiki-platform-logging-ui

Package

Name
org.xwiki.platform:xwiki-platform-logging-ui
View open source insights on deps.dev
Purl
pkg:maven/org.xwiki.platform/xwiki-platform-logging-ui

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14.5
Fixed
14.10