PT-2022-20581 · Xwiki · Xwiki Platform Security Parent Pom

Published

2022-09-07

·

Updated

2022-09-20

·

CVE-2022-31167

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions XWiki Platform Security Parent POM versions 5.0 through 12.10.10 XWiki Platform Security Parent POM versions 13.0.0 through 13.4.5 XWiki Platform Security Parent POM versions 13.5.0 through 13.10.0
Description A bug in the security cache stores rules associated to document and space with the same name in the same cache entry. This allows overwriting the rights of a space or a document by creating a page with the same name and checking its rights first, causing them to be used for the other as well.
Recommendations For versions 5.0 through 12.10.10, update to version 12.10.11 or later. For versions 13.0.0 through 13.4.5, update to version 13.4.6 or later. For versions 13.5.0 through 13.10.0, update to version 13.10.1 or later.

Exploit

Fix

Missing Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-31167
GHSA-GG53-WF5X-R3R6

Affected Products

Xwiki Platform Security Parent Pom