PT-2022-24946 · Xwiki · Xwiki Oidc

Clément Aubin

·

Published

2022-11-04

·

Updated

2022-11-07

·

CVE-2022-39387

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions XWiki OIDC versions prior to 1.29.1
Description The issue allows an attacker to bypass XWiki authentication by specifying their own OpenID provider through request parameters, such as oidc.endpoint.*, or by using an XWiki-based OpenID provider with oidc.xwikiprovider. Additionally, an attacker can provide a specific group mapping through oidc.groups.mapping to automatically become part of the XWikiAdminGroup.
Recommendations For versions prior to 1.29.1, upgrade to version 1.29.1 to resolve the issue. There is no workaround, and an upgrade of the authenticator is required.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-39387
GHSA-M7GV-V8XX-V47W

Affected Products

Xwiki Oidc