PT-2023-8621 · Xwiki · Identity-Oauth-Ui

Lucaswitvoet

·

Published

2023-10-16

·

Updated

2023-10-20

·

CVE-2023-45144

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions com.xwiki.identity-oauth:identity-oauth-ui versions prior to 1.6
Description The issue is related to the lack of protection of the web page structure, allowing a remote attacker to conduct a cross-site scripting (XSS) attack. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request are vulnerable to XSS and XWiki syntax injection, enabling remote code execution via the groovy macro. This affects the confidentiality, integrity, and availability of the whole XWiki installation.
Recommendations For versions prior to 1.6, upgrade to Identity OAuth version 1.6 to fix the issue. As a temporary workaround, consider restricting access to the groovy macro to minimize the risk of exploitation. There are no known workarounds besides upgrading.

Exploit

Fix

Code Injection

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-01274
CVE-2023-45144
GHSA-H2RM-29CH-WFMH

Affected Products

Identity-Oauth-Ui