PT-2022-16899 · Xwiki · Xwiki Platform

Guillaume Coquard

·

Published

2022-04-08

·

Updated

2022-04-15

·

CVE-2022-24819

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions XWiki Platform versions prior to 12.10.11 XWiki Platform versions prior to 13.4.4 XWiki Platform versions prior to 13.9-rc-1
Description A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
Recommendations For XWiki Platform versions prior to 12.10.11, update to version 12.10.11 or later. For XWiki Platform versions prior to 13.4.4, update to version 13.4.4 or later. For XWiki Platform versions prior to 13.9-rc-1, update to version 13.9-rc-1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24819
GHSA-97JG-43C9-Q6PF

Affected Products

Xwiki Platform