It's possible to make XWiki create many new schemas and fill them with tables just by using a crafted user identifier in the login form.
The problem has been patched in XWiki 13.10.8, 14.6RC1 and 14.4.2.
The only workarounds for this are: * use an authenticator which does interpret the login as a reference to a document * using a different database than PostgreSQL * upgrade XWiki
https://jira.xwiki.org/browse/XWIKI-19886
If you have any questions or comments about this advisory: * Open an issue in Jira XWiki.org * Email us at Security Mailing List
{ "nvd_published_at": "2022-11-23T21:15:00Z", "cwe_ids": [ "CWE-400", "CWE-770" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-11-21T22:36:49Z" }