PT-2022-20580 · Xwiki · Xwiki-Platform-Oldcore
Anca Luca
·
Published
2022-09-07
·
Updated
2022-09-20
·
CVE-2022-31166
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
XWiki Platform Old Core versions 11.3.7 through 12.0RC1
XWiki Platform Old Core version 11.0.3
Description
A bug in XWikiRights resolution of groups can be exploited to obtain privilege escalation. Editing a right with the object editor leads to adding a supplementary empty value to groups, which is then resolved as a reference to XWiki.WebHome page. Adding an XWikiGroup xobject to that page transforms it to a group, and any user put in that group would then obtain the privileges related to the edited right. This issue is normally mitigated by the fact that XWiki.WebHome should be protected by default for edit rights.
Recommendations
For XWiki Platform Old Core versions 11.3.7 through 12.0RC1, update to version 13.10.4 or later to patch the issue.
For XWiki Platform Old Core version 11.0.3, update to version 13.10.4 or later to patch the issue.
As a temporary workaround, set appropriate rights on XWiki.WebHome page to prevent users from editing it.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki-Platform-Oldcore