PT-2024-21295 · Xwiki · Xwiki Application Licensing

Oanalavinia

·

Published

2024-02-21

·

Updated

2024-02-22

·

CVE-2024-26138

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions XWiki Application Licensing versions prior to 1.24.2
Description The XWiki licensor application includes a public document Licenses.Code.LicenseJSON that exposes sensitive information, including the instance's id, first and last name, and email of the license owner. This information leak can be used for targeted phishing attacks. The instance id can be associated with active installs data, and email addresses might be displayed obfuscated depending on the configuration.
Recommendations For versions prior to 1.24.2, upgrade to Application Licensing 1.24.2 to fix the issue. There are no known workarounds besides upgrading. As a temporary workaround, consider restricting access to the Licenses.Code.LicenseJSON document until the upgrade is applied.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-26138
GHSA-4HFP-M9GV-M753

Affected Products

Xwiki Application Licensing