PT-2021-19889 · Xwiki · Xwiki Platform
Simon Urli
·
Published
2021-07-01
·
Updated
2022-07-02
·
CVE-2021-32729
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions prior to 12.6.8
XWiki Platform versions prior to 12.10.4
XWiki Platform versions prior to 13.0
Description
A vulnerability exists in the XWiki Platform where the script service method used to reset the authentication failures record can be executed by any user with Script rights, without requiring Programming rights. This allows an attacker with script rights to potentially perform a brute force attack by resetting the authentication failure record, effectively deactivating the mechanism meant to mitigate such attacks.
Recommendations
For versions prior to 12.6.8, upgrade to version 12.6.8 or later.
For versions prior to 12.10.4, upgrade to version 12.10.4 or later.
For versions prior to 13.0, upgrade to version 13.0 or later.
As a temporary workaround, consider restricting Script right access to trusted users to minimize the risk of exploitation. Monitor logs for signs of brute force attacks on authentication, as authentication failures are logged.
Fix
Improper Authentication
Protection Mechanism Failure
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xwiki Platform