CVE-2022-24821
Incorrect Use of Privileged APIs in org.xwiki.platform.skin.skinx
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Simple users can create global SSX/JSX without specific rights: in theory only users with Programming Rights should be allowed to create SSX or JSX that are executed everywhere on a wiki. But a bug allow anyone with edit rights to actually create those. This issue has been patched in XWiki 13.10-rc-1, 12.10.11 and 13.4.6. There's no easy workaround for this issue, administrators should upgrade their wiki.
La plataforma XWiki es una plataforma wiki genérica que ofrece servicios de tiempo de ejecución para aplicaciones construidas sobre ella. Los usuarios simples pueden crear SSX/JSX globales sin derechos específicos: en teoría, sólo los usuarios con derechos de programación deberían poder crear SSX o JSX que sean ejecutados en cualquier lugar de un wiki. Pero un error permite que cualquiera con derechos de edición pueda crearlos. Este problema ha sido parcheado en XWiki versiones 13.10-rc-1, 12.10.11 y 13.4.6. No se presenta una mitigación fácil para este problema, los administradores deben actualizar su wiki
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-10 CVE Reserved
- 2022-04-08 CVE Published
- 2023-10-30 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-648: Incorrect Use of Privileged APIs
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-ghcq-472w-vf4h | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://jira.xwiki.org/browse/XWIKI-19155 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xwiki Search vendor "Xwiki" | Xwiki Search vendor "Xwiki" for product "Xwiki" | >= 12.0.0 < 12.10.11 Search vendor "Xwiki" for product "Xwiki" and version " >= 12.0.0 < 12.10.11" | - |
Affected
| ||||||
Xwiki Search vendor "Xwiki" | Xwiki Search vendor "Xwiki" for product "Xwiki" | >= 13.4.0 < 13.4.6 Search vendor "Xwiki" for product "Xwiki" and version " >= 13.4.0 < 13.4.6" | - |
Affected
| ||||||
Xwiki Search vendor "Xwiki" | Xwiki Search vendor "Xwiki" for product "Xwiki" | 13.10 Search vendor "Xwiki" for product "Xwiki" and version "13.10" | - |
Affected
|