Any user with an account on the main wiki could run scheduling operations on subwikis.
To reproduce, as a user on the main wiki without any special right, view the document Scheduler.WebHome in a subwiki. Then, click on any operation (e.g., Trigger) on any job. If the operation is successful, then the instance is vulnerable.
This has been patched in XWiki 15.10.9 and 16.3.0.
If you have subwikis where the Job Scheduler is enabled, you can edit the objects on Scheduler.WebPreferences to match https://github.com/xwiki/xwiki-platform/commit/54bcc5a7a2e440cc591b91eece9c13dc0c487331#diff-8e274bd0065e319a34090339de6dfe56193144d15fd71c52c1be7272254728b4.
If you have any questions or comments about this advisory: * Open an issue in Jira XWiki.org * Email us at Security Mailing List
{
"nvd_published_at": "2024-12-12T19:15:14Z",
"github_reviewed_at": "2024-12-12T19:21:16Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-862"
],
"github_reviewed": true
}