PT-2022-24946 · Xwiki · Xwiki Oidc
Clément Aubin
·
Published
2022-11-04
·
Updated
2022-11-07
·
CVE-2022-39387
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
XWiki OIDC versions prior to 1.29.1
Description
The issue allows an attacker to bypass XWiki authentication by specifying their own OpenID provider through request parameters, such as
oidc.endpoint.*, or by using an XWiki-based OpenID provider with oidc.xwikiprovider. Additionally, an attacker can provide a specific group mapping through oidc.groups.mapping to automatically become part of the XWikiAdminGroup.Recommendations
For versions prior to 1.29.1, upgrade to version 1.29.1 to resolve the issue. There is no workaround, and an upgrade of the authenticator is required.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki Oidc