[MAVEN:GHSA-GF7X-2J2X-7F73] Missing authorization in xwiki-platform

Severity Moderate
Affected Packages 2
Fixed Packages 2
CVEs 1

Impact

Any user with edit right can copy the content of a page it does not have access to by using it as template of a new page.

Patches

It has been patched in XWiki 13.2CR1 and 12.10.6

Workarounds

There is no workaround beside patching.

References

https://jira.xwiki.org/browse/XWIKI-18430

For more information

If you have any questions or comments about this advisory:
* Open an issue in Jira XWiki
* Email us at our security mailing list

ID
MAVEN:GHSA-GF7X-2J2X-7F73
Severity
moderate
URL
https://github.com/advisories/GHSA-gf7x-2j2x-7f73
Published
2022-02-09T21:41:46
(2 years ago)
Modified
2023-02-03T05:05:53
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.xwiki.platform/xwiki-platform-oldcore org.xwiki.platform xwiki-platform-oldcore >= 13.0 <= 13.1
Fixed pkg:maven/org.xwiki.platform/xwiki-platform-oldcore org.xwiki.platform xwiki-platform-oldcore = 13.2-rc-1
Affected pkg:maven/org.xwiki.platform/xwiki-platform-oldcore org.xwiki.platform xwiki-platform-oldcore < 12.10.6
Fixed pkg:maven/org.xwiki.platform/xwiki-platform-oldcore org.xwiki.platform xwiki-platform-oldcore = 12.10.6
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...