PT-2022-16899 · Xwiki · Xwiki Platform
Guillaume Coquard
·
Published
2022-04-08
·
Updated
2022-04-15
·
CVE-2022-24819
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions prior to 12.10.11
XWiki Platform versions prior to 13.4.4
XWiki Platform versions prior to 13.9-rc-1
Description
A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
Recommendations
For XWiki Platform versions prior to 12.10.11, update to version 12.10.11 or later.
For XWiki Platform versions prior to 13.4.4, update to version 13.4.4 or later.
For XWiki Platform versions prior to 13.9-rc-1, update to version 13.9-rc-1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki Platform