CVE-2023-26471

XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in restricted mode (anything dangerous is disabled), but the async macro does not take into account the restricted mode. This means that any user with comment right can use the async macro to make it execute any wiki content with the right of superadmin. This has been patched in XWiki 14.9, 14.4.6, and 13.10.10. The only known workaround consists of applying a patch and rebuilding and redeploying `org.xwiki.platform:xwiki-platform-rendering-async-macro`.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:11.6:rc1:*:*:*:*:*:*

History

13 Mar 2023, 16:31

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:11.6:rc1:*:*:*:*:*:*
References (MISC) https://jira.xwiki.org/browse/XWIKI-20234 - (MISC) https://jira.xwiki.org/browse/XWIKI-20234 - Exploit, Issue Tracking, Patch, Vendor Advisory
References (MISC) https://github.com/xwiki/xwiki-platform/commit/00532d9f1404287cf3ec3a05056640d809516006 - (MISC) https://github.com/xwiki/xwiki-platform/commit/00532d9f1404287cf3ec3a05056640d809516006 - Patch
References (MISC) https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-9cqm-5wf7-wcj7 - (MISC) https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-9cqm-5wf7-wcj7 - Vendor Advisory

02 Mar 2023, 20:11

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-02 19:15

Updated : 2024-02-04 23:14


NVD link : CVE-2023-26471

Mitre link : CVE-2023-26471

CVE.ORG link : CVE-2023-26471


JSON object : View

Products Affected

xwiki

  • xwiki
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control