PT-2023-8615 · Xwiki · Xwiki Platform

Bruhbey

·

Publicado

2023-10-25

·

Atualizado

2023-10-31

·

CVE-2023-37910

CVSS v2.0

8.5

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions XWiki Platform versions 14.0-rc-1 through 14.4.7 XWiki Platform versions 14.0-rc-1 through 14.10.3 XWiki Platform versions 14.0-rc-1 through 14.9.x XWiki Platform version 15.0-rc-1 is not affected, but versions prior to it are
Description The issue is related to errors in authorization, allowing a remote attacker to edit arbitrary documents. An attacker with edit access on any document can move any attachment of any other document to this attacker-controlled document, accessing and possibly publishing any attachment of which the name is known, regardless of view or edit rights on the source document. The attachment is deleted from the source document.
Recommendations For XWiki Platform versions 14.0-rc-1 through 14.4.7, upgrade to version 14.4.8. For XWiki Platform versions 14.0-rc-1 through 14.10.3, upgrade to version 14.10.4. For XWiki Platform versions 14.0-rc-1 through 14.9.x, upgrade to a fixed version. As a temporary workaround, consider restricting access to the attachment move feature until a patch is available.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-01268
CVE-2023-37910
GHSA-RWWX-6572-MP29

Produtos afetados

Xwiki Platform