GHSA-f963-4cq8-2gw7

Suggest an improvement
Source
https://github.com/advisories/GHSA-f963-4cq8-2gw7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-f963-4cq8-2gw7/GHSA-f963-4cq8-2gw7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f963-4cq8-2gw7
Aliases
Published
2024-08-19T21:49:15Z
Modified
2024-08-19T22:12:04.199287Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
  • 9.4 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
In XWiki Platform, payloads stored in content is executed when a user with script/programming right edit them
Details

Impact

A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The user with elevated rights is not warned beforehand that they are going to edit possibly dangerous content. The payload is executed at edit time.

Patches

This vulnerability has been patched in XWiki 15.10RC1.

Workarounds

No workaround. It is advised to upgrade to XWiki 15.10+.

References

  • https://jira.xwiki.org/browse/XWIKI-20331
  • https://jira.xwiki.org/browse/XWIKI-21311
  • https://jira.xwiki.org/browse/XWIKI-21481
  • https://jira.xwiki.org/browse/XWIKI-21482
  • https://jira.xwiki.org/browse/XWIKI-21483
  • https://jira.xwiki.org/browse/XWIKI-21484
  • https://jira.xwiki.org/browse/XWIKI-21485
  • https://jira.xwiki.org/browse/XWIKI-21486
  • https://jira.xwiki.org/browse/XWIKI-21487
  • https://jira.xwiki.org/browse/XWIKI-21488
  • https://jira.xwiki.org/browse/XWIKI-21489
  • https://jira.xwiki.org/browse/XWIKI-21490

For more information

If you have any questions or comments about this advisory: * Open an issue in Jira XWiki.org * Email us at Security Mailing List

Attribution

This vulnerability has been reported on Intigriti by @floerer

Database specific
{
    "nvd_published_at": "2024-08-19T17:15:09Z",
    "cwe_ids": [
        "CWE-269",
        "CWE-862"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2024-08-19T21:49:15Z"
}
References

Affected packages

Maven / org.xwiki.platform:xwiki-platform-web-templates

Package

Name
org.xwiki.platform:xwiki-platform-web-templates
View open source insights on deps.dev
Purl
pkg:maven/org.xwiki.platform/xwiki-platform-web-templates

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
15.10-rc-1