GHSA-qcj3-wpgm-qpxh

Suggest an improvement
Source
https://github.com/advisories/GHSA-qcj3-wpgm-qpxh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-qcj3-wpgm-qpxh/GHSA-qcj3-wpgm-qpxh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qcj3-wpgm-qpxh
Aliases
Published
2024-06-24T18:00:16Z
Modified
2024-06-24T21:27:57Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
XWiki programming rights may be inherited by inclusion
Details

Impact

The content of a document included using {{include reference="targetdocument"/}} is executed with the right of the includer and not with the right of its author.

This means that any user able to modify the target document can impersonate the author of the content which used the include macro.

Patches

This has been patched in XWiki 15.0 RC1 by making the default behavior safe.

Workarounds

Make sure to protect any included document to make sure only allowed users can modify it.

A workaround have been provided in 14.10.2 to allow forcing to execute the included content with the target content author instead of the default behavior. See https://extensions.xwiki.org/xwiki/bin/view/Extension/Include%20Macro#HAuthor for more details.

References

https://jira.xwiki.org/browse/XWIKI-5027 https://jira.xwiki.org/browse/XWIKI-20471

For more information

If you have any questions or comments about this advisory: * Open an issue in Jira XWiki.org * Email us at Security Mailing List

Database specific
{
    "nvd_published_at": "2024-06-24T17:15:10Z",
    "cwe_ids": [
        "CWE-863"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2024-06-24T18:00:16Z"
}
References

Affected packages

Maven / org.xwiki.platform:xwiki-platform-rendering-macro-include

Package

Name
org.xwiki.platform:xwiki-platform-rendering-macro-include
View open source insights on deps.dev
Purl
pkg:maven/org.xwiki.platform/xwiki-platform-rendering-macro-include

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
15.0-rc-1