org.xwiki.platform:xwiki-platform-oldcore makes Incorrect Use of Privileged APIs with DocumentAuthors
Critical severity
GitHub Reviewed
Published
Apr 12, 2023
in
xwiki/xwiki-platform
•
Updated May 5, 2023
Package
Affected versions
>= 14.5, < 14.10
>= 14.4.1, < 14.4.7
Patched versions
14.10
14.4.7
Description
Published to the GitHub Advisory Database
Apr 12, 2023
Reviewed
Apr 12, 2023
Published by the National Vulnerability Database
Apr 16, 2023
Last updated
May 5, 2023
Impact
The Document script API returns directly a DocumentAuthors allowing to set any authors to the document, which in consequence can allow subsequent executions of scripts since this author is used for checking rights.
Example of such attack:
Patches
The problem has been patched in XWiki 14.10 and 14.4.7 by returning a safe script API.
Workarounds
There no easy workaround apart of upgrading.
References
For more information
If you have any questions or comments about this advisory:
References