CVE-2023-26471

XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in restricted mode (anything dangerous is disabled), but the async macro does not take into account the restricted mode. This means that any user with comment right can use the async macro to make it execute any wiki content with the right of superadmin. This has been patched in XWiki 14.9, 14.4.6, and 13.10.10. The only known workaround consists of applying a patch and rebuilding and redeploying `org.xwiki.platform:xwiki-platform-rendering-async-macro`.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:11.6:rc1:*:*:*:*:*:*

History

21 Nov 2024, 07:51

Type Values Removed Values Added
References () https://github.com/xwiki/xwiki-platform/commit/00532d9f1404287cf3ec3a05056640d809516006 - Patch () https://github.com/xwiki/xwiki-platform/commit/00532d9f1404287cf3ec3a05056640d809516006 - Patch
References () https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-9cqm-5wf7-wcj7 - Vendor Advisory () https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-9cqm-5wf7-wcj7 - Vendor Advisory
References () https://jira.xwiki.org/browse/XWIKI-20234 - Exploit, Issue Tracking, Patch, Vendor Advisory () https://jira.xwiki.org/browse/XWIKI-20234 - Exploit, Issue Tracking, Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 9.9

Information

Published : 2023-03-02 19:15

Updated : 2024-11-21 07:51


NVD link : CVE-2023-26471

Mitre link : CVE-2023-26471

CVE.ORG link : CVE-2023-26471


JSON object : View

Products Affected

xwiki

  • xwiki
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo