[MAVEN:GHSA-8CW6-4R32-6R3H] XWiki Platform may allow privilege escalation to programming rights via user's first name

Severity Critical
Affected Packages 3
Fixed Packages 3
CVEs 1

Impact

Any user can edit his own profile and inject code which is going to be executed with programming right.

Steps to reproduce:

  • Set your first name to


{{cache id="userProfile"}}{{groovy}}println("Hello from groovy!"){{/groovy}}{{/cache}}

The first name appears as interpreted "Hello from groovy" instead of the expected fully escaped "{{cache id="userProfile"}}{{groovy}}println("Hello from groovy!"){{/groovy}}{{/cache}}".

The same vulnerability can also be exploited in all other places where short text properties are displayed, e.g., in apps created using Apps Within Minutes that use a short text field.

Patches

The problem has been patched on versions 13.10.9, 14.4.4, 14.7RC1.

Workarounds

There are no other workarounds than upgrading XWiki or patching the xwiki-commons-xml JAR file.

References

For more information

If you have any questions or comments about this advisory:
* Open an issue in Jira XWiki.org
* Email us at Security Mailing List

Package Affected Version
pkg:maven/org.xwiki.commons/xwiki-commons-xml >= 14.5, < 14.7-rc-1
pkg:maven/org.xwiki.commons/xwiki-commons-xml >= 14.0-rc-1, < 14.4.4
pkg:maven/org.xwiki.commons/xwiki-commons-xml >= 3.1-milestone-1, < 13.10.9
ID
MAVEN:GHSA-8CW6-4R32-6R3H
Severity
critical
URL
https://github.com/advisories/GHSA-8cw6-4r32-6r3h
Published
2023-03-03T22:49:27
(18 months ago)
Modified
2023-03-03T22:49:28
(18 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.xwiki.commons/xwiki-commons-xml org.xwiki.commons xwiki-commons-xml >= 14.5 < 14.7-rc-1
Fixed pkg:maven/org.xwiki.commons/xwiki-commons-xml org.xwiki.commons xwiki-commons-xml = 14.7-rc-1
Affected pkg:maven/org.xwiki.commons/xwiki-commons-xml org.xwiki.commons xwiki-commons-xml >= 14.0-rc-1 < 14.4.4
Fixed pkg:maven/org.xwiki.commons/xwiki-commons-xml org.xwiki.commons xwiki-commons-xml = 14.4.4
Affected pkg:maven/org.xwiki.commons/xwiki-commons-xml org.xwiki.commons xwiki-commons-xml >= 3.1-milestone-1 < 13.10.9
Fixed pkg:maven/org.xwiki.commons/xwiki-commons-xml org.xwiki.commons xwiki-commons-xml = 13.10.9
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...