Any user with edit right can copy the content of a page it does not have access to by using it as template of a new page.
It has been patched in XWiki 13.2CR1 and 12.10.6
There is no workaround beside patching.
https://jira.xwiki.org/browse/XWIKI-18430
If you have any questions or comments about this advisory: * Open an issue in Jira XWiki * Email us at our security mailing list
{ "nvd_published_at": "2022-02-09T21:15:00Z", "github_reviewed_at": "2022-02-09T21:41:46Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-862" ] }