PT-2021-19889 · Xwiki · Xwiki Platform

Simon Urli

·

Published

2021-07-01

·

Updated

2022-07-02

·

CVE-2021-32729

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions XWiki Platform versions prior to 12.6.8 XWiki Platform versions prior to 12.10.4 XWiki Platform versions prior to 13.0
Description A vulnerability exists in the XWiki Platform where the script service method used to reset the authentication failures record can be executed by any user with Script rights, without requiring Programming rights. This allows an attacker with script rights to potentially perform a brute force attack by resetting the authentication failure record, effectively deactivating the mechanism meant to mitigate such attacks.
Recommendations For versions prior to 12.6.8, upgrade to version 12.6.8 or later. For versions prior to 12.10.4, upgrade to version 12.10.4 or later. For versions prior to 13.0, upgrade to version 13.0 or later. As a temporary workaround, consider restricting Script right access to trusted users to minimize the risk of exploitation. Monitor logs for signs of brute force attacks on authentication, as authentication failures are logged.

Fix

Improper Authentication

Protection Mechanism Failure

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32729
GHSA-M738-3RC4-5XV3

Affected Products

Xwiki Platform