GHSA-xh35-w7wg-95v3

Suggest an improvement
Source
https://github.com/advisories/GHSA-xh35-w7wg-95v3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-xh35-w7wg-95v3/GHSA-xh35-w7wg-95v3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xh35-w7wg-95v3
Aliases
Published
2024-01-08T16:25:58Z
Modified
2024-01-09T16:12:35Z
Severity
  • 8.0 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
XWiki has no right protection on rollback action
Details

Impact

The rollback action is missing a right protection: it means that a user can rollback to a previous version of the page to gain rights they don't have anymore. This vulnerability impacts all version of XWiki since rollback action is available.

Patches

The problem has been patched in XWiki 14.10.16, 15.5.3 and 15.8-rc-1 by ensuring that the rights are checked before performing the rollback.

Workarounds

There's no workaround for this vulnerability, except paying attention to delete old versions of documents that could allow users to gain more rights.

References

For more information

If you have any questions or comments about this advisory: * Open an issue in Jira XWiki.org * Email us at Security Mailing List

Database specific
{
    "nvd_published_at": "2024-01-09T00:15:44Z",
    "cwe_ids": [
        "CWE-274"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2024-01-08T16:25:58Z"
}
References

Affected packages

Maven / org.xwiki.platform:xwiki-platform-oldcore

Package

Name
org.xwiki.platform:xwiki-platform-oldcore
View open source insights on deps.dev
Purl
pkg:maven/org.xwiki.platform/xwiki-platform-oldcore

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0
Fixed
14.10.17

Maven / org.xwiki.platform:xwiki-platform

Package

Name
org.xwiki.platform:xwiki-platform
View open source insights on deps.dev
Purl
pkg:maven/org.xwiki.platform/xwiki-platform

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15.0-rc-1
Fixed
15.5.3

Maven / org.xwiki.platform:xwiki-platform

Package

Name
org.xwiki.platform:xwiki-platform
View open source insights on deps.dev
Purl
pkg:maven/org.xwiki.platform/xwiki-platform

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15.6-rc-1
Fixed
15.8-rc-1