CVE-2022-23618 – Open Redirect in xwiki-platform
https://notcve.org/view.php?id=CVE-2022-23618
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions there is no protection against URL redirection to untrusted sites, in particular some well known parameters (xredirect) can be used to perform url redirections. This problem has been patched in XWiki 12.10.7 and XWiki 13.3RC1. Users are advised to update. There are no known workarounds for this issue. • https://github.com/xwiki/xwiki-platform/commit/5251c02080466bf9fb55288f04a37671108f8096 https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-jp55-vvmf-63mv https://jira.xwiki.org/browse/XWIKI-10309 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2022-23617 – Missing authorization in xwiki-platform
https://notcve.org/view.php?id=CVE-2022-23617
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit right can copy the content of a page it does not have access to by using it as template of a new page. This issue has been patched in XWiki 13.2CR1 and 12.10.6. Users are advised to update. There are no known workarounds for this issue. • https://github.com/xwiki/xwiki-platform/commit/30c52b01559b8ef5ed1035dac7c34aaf805764d5 https://github.com/xwiki/xwiki-platform/commit/b35ef0edd4f2ff2c974cbeef6b80fcf9b5a44554 https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-gf7x-2j2x-7f73 https://jira.xwiki.org/browse/XWIKI-18430 • CWE-862: Missing Authorization •
CVE-2022-23616 – Remote code execution in xwiki-platform
https://notcve.org/view.php?id=CVE-2022-23616
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for an unprivileged user to perform a remote code execution by injecting a groovy script in her own profile and by calling the Reset password feature since the feature is performing a save of the user profile with programming rights in the impacted versions of XWiki. The issue has been patched in XWiki 13.1RC1. There are two different possible workarounds, each consisting of modifying the XWiki/ResetPassword page. 1. The Reset password feature can be entirely disabled by deleting the XWiki/ResetPassword page. 2. • https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-mgjw-2wrp-r535 https://jira.xwiki.org/browse/XWIKI-16661 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •
CVE-2022-23615 – Partial authorization bypass on document save in xwiki-platform
https://notcve.org/view.php?id=CVE-2022-23615
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can save a document with the right of the current user which allow accessing API requiring programming right if the current user has programming right. This has been patched in XWiki 13.0. Users are advised to update to resolve this issue. The only known workaround is to limit SCRIPT access. • https://github.com/xwiki/xwiki-platform/commit/7ab0fe7b96809c7a3881454147598d46a1c9bbbe https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-f4cj-3q3h-884r https://jira.xwiki.org/browse/XWIKI-5024 • CWE-863: Incorrect Authorization •
CVE-2021-43841 – XSS by SVG upload in xwiki-platform
https://notcve.org/view.php?id=CVE-2021-43841
XWiki is a generic wiki platform offering runtime services for applications built on top of it. When using default XWiki configuration, it's possible for an attacker to upload an SVG containing a script executed when executing the download action on the file. This problem has been patched so that the default configuration doesn't allow to display the SVG files in the browser. Users are advised to update or to disallow uploads of SVG files. XWiki es una plataforma wiki genérica que ofrece servicios de tiempo de ejecución para aplicaciones construidas sobre ella. • https://github.com/xwiki/xwiki-platform/commit/5853d492b3a274db0d94d560e2a5ea988a271c62 https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-9jq9-c2cv-pcrj https://jira.xwiki.org/browse/XWIKI-18368 https://www.xwiki.org/xwiki/bin/view/Documentation/AdminGuide/Attachments#HAttachmentdisplayordownload • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •