GHSA-4f8g-fq6x-jqrr

Suggest an improvement
Source
https://github.com/advisories/GHSA-4f8g-fq6x-jqrr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-4f8g-fq6x-jqrr/GHSA-4f8g-fq6x-jqrr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4f8g-fq6x-jqrr
Aliases
Published
2023-04-12T20:34:55Z
Modified
2023-11-08T04:12:17.759007Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
org.xwiki.platform:xwiki-platform-oldcore vulnerable to data leak through deleted documents
Details

Impact

Rights added to a document are not taken into account for viewing it once it's deleted. Note that this vulnerability only impact deleted documents that where containing view rights: the view rights provided on a space of a deleted document are properly checked.

Patches

The problem has been patched in XWiki 14.10 by checking the rights of current user: only admin and deleter of the document are allowed to view it.

Workarounds

There is no workaround for this vulnerability other than upgrading.

References

  • Jira ticket: https://jira.xwiki.org/browse/XWIKI-16285
  • Commit: https://github.com/xwiki/xwiki-platform/commit/d9e947559077e947315bf700c5703dfc7dd8a8d7

For more information

If you have any questions or comments about this advisory: * Open an issue in Jira * Email us at security ML

Database specific
{
    "nvd_published_at": "2023-04-15T16:15:00Z",
    "github_reviewed_at": "2023-04-12T20:34:55Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-668"
    ]
}
References

Affected packages

Maven / org.xwiki.platform:xwiki-platform-oldcore

Package

Name
org.xwiki.platform:xwiki-platform-oldcore
View open source insights on deps.dev
Purl
pkg:maven/org.xwiki.platform/xwiki-platform-oldcore

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.2-milestone-1
Fixed
13.10.11

Maven / org.xwiki.platform:xwiki-platform-oldcore

Package

Name
org.xwiki.platform:xwiki-platform-oldcore
View open source insights on deps.dev
Purl
pkg:maven/org.xwiki.platform/xwiki-platform-oldcore

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14.0-rc-1
Fixed
14.4.7

Maven / org.xwiki.platform:xwiki-platform-oldcore

Package

Name
org.xwiki.platform:xwiki-platform-oldcore
View open source insights on deps.dev
Purl
pkg:maven/org.xwiki.platform/xwiki-platform-oldcore

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14.5
Fixed
14.10