PT-2023-26180 · Xwiki · Xwiki Platform

Michael Hamann

·

Published

2023-10-25

·

Updated

2023-10-31

·

CVE-2023-37911

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions XWiki Platform versions 9.4-rc-1 through 14.10.7 XWiki Platform versions 15.3-rc-1 and earlier
Description The issue arises when a document has been deleted and re-created, allowing users with view rights on the re-created document but not on the deleted document to view the contents of the deleted document. This can be exploited through the diff feature and partially through the REST API by using versions such as deleted:1. Given sufficient rights, the attacker can also re-create the deleted document, extending the scope to any deleted document as long as the attacker has edit rights in the location of the deleted document.
Recommendations For XWiki Platform versions 9.4-rc-1 through 14.10.7, update to version 14.10.8 to properly check rights when deleted revisions of a document are accessed. For XWiki Platform versions 15.3-rc-1 and earlier, update to version 15.3 RC1 to properly check rights when deleted revisions of a document are accessed. As a temporary workaround, consider regularly cleaning deleted documents to minimize the potential exposure. Extra care should be taken when deleting sensitive documents that are protected individually or deleting a protected space as a whole.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2023-37911
GHSA-GH64-QXH5-4M33

Affected Products

Xwiki Platform