PT-2022-20580 · Xwiki · Xwiki-Platform-Oldcore

Anca Luca

·

Published

2022-09-07

·

Updated

2022-09-20

·

CVE-2022-31166

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions XWiki Platform Old Core versions 11.3.7 through 12.0RC1 XWiki Platform Old Core version 11.0.3
Description A bug in XWikiRights resolution of groups can be exploited to obtain privilege escalation. Editing a right with the object editor leads to adding a supplementary empty value to groups, which is then resolved as a reference to XWiki.WebHome page. Adding an XWikiGroup xobject to that page transforms it to a group, and any user put in that group would then obtain the privileges related to the edited right. This issue is normally mitigated by the fact that XWiki.WebHome should be protected by default for edit rights.
Recommendations For XWiki Platform Old Core versions 11.3.7 through 12.0RC1, update to version 13.10.4 or later to patch the issue. For XWiki Platform Old Core version 11.0.3, update to version 13.10.4 or later to patch the issue. As a temporary workaround, set appropriate rights on XWiki.WebHome page to prevent users from editing it.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2022-31166
GHSA-G4H6-QP44-WQVX

Affected Products

Xwiki-Platform-Oldcore