PT-2024-36595 · Xwiki · Xwiki Platform

Michael Hamann

·

Published

2024-12-12

·

Updated

2024-12-13

·

CVE-2024-55876

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions XWiki Platform versions 1.2-milestone-2 through 15.10.8 XWiki Platform versions 1.2-milestone-2 through 16.2.x
Description The issue allows any user with an account on the main wiki to run scheduling operations on subwikis. To reproduce, a user on the main wiki without any special right can view the document Scheduler.WebHome in a subwiki, then click on any operation (e.g., Trigger) on any job. If the operation is successful, the instance is vulnerable.
Recommendations For XWiki Platform versions 1.2-milestone-2 through 15.10.8, update to version 15.10.9 or later. For XWiki Platform versions 1.2-milestone-2 through 16.2.x, update to version 16.3.0 or later. As a temporary workaround, those who have subwikis where the Job Scheduler is enabled can edit the objects on Scheduler.WebPreferences to match the patch.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-55876
GHSA-CWQ6-MJMX-47P6

Affected Products

Xwiki Platform