PT-2024-36595 · Xwiki · Xwiki Platform
Michael Hamann
·
Published
2024-12-12
·
Updated
2024-12-13
·
CVE-2024-55876
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions 1.2-milestone-2 through 15.10.8
XWiki Platform versions 1.2-milestone-2 through 16.2.x
Description
The issue allows any user with an account on the main wiki to run scheduling operations on subwikis. To reproduce, a user on the main wiki without any special right can view the document
Scheduler.WebHome in a subwiki, then click on any operation (e.g., Trigger) on any job. If the operation is successful, the instance is vulnerable.Recommendations
For XWiki Platform versions 1.2-milestone-2 through 15.10.8, update to version 15.10.9 or later.
For XWiki Platform versions 1.2-milestone-2 through 16.2.x, update to version 16.3.0 or later.
As a temporary workaround, those who have subwikis where the Job Scheduler is enabled can edit the objects on
Scheduler.WebPreferences to match the patch.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xwiki Platform