CVE-2023-45144

com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and XWiki syntax injection. This allows remote code execution via the groovy macro and thus affects the confidentiality, integrity and availability of the whole XWiki installation. The issue has been fixed in Identity OAuth version 1.6. There are no known workarounds for this vulnerability and users are advised to upgrade.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xwiki:oauth_identity:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:26

Type Values Removed Values Added
References () https://github.com/xwikisas/identity-oauth/blob/master/ui/src/main/resources/IdentityOAuth/LoginUIExtension.vm#L58 - Broken Link () https://github.com/xwikisas/identity-oauth/blob/master/ui/src/main/resources/IdentityOAuth/LoginUIExtension.vm#L58 - Broken Link
References () https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6 - Patch () https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6 - Patch
References () https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6#diff-2ab2e0716443d790d7d798320e4a45151661f4eca5440331f4a227b29c87c188 - Patch () https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6#diff-2ab2e0716443d790d7d798320e4a45151661f4eca5440331f4a227b29c87c188 - Patch
References () https://github.com/xwikisas/identity-oauth/security/advisories/GHSA-h2rm-29ch-wfmh - Vendor Advisory () https://github.com/xwikisas/identity-oauth/security/advisories/GHSA-h2rm-29ch-wfmh - Vendor Advisory
References () https://jira.xwiki.org/browse/XWIKI-20719 - Permissions Required () https://jira.xwiki.org/browse/XWIKI-20719 - Permissions Required
CVSS v2 : unknown
v3 : 9.6
v2 : unknown
v3 : 10.0

20 Oct 2023, 20:00

Type Values Removed Values Added
CPE cpe:2.3:a:xwiki:oauth_identity:*:*:*:*:*:*:*:*
CWE CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.6
First Time Xwiki oauth Identity
Xwiki
References (MISC) https://jira.xwiki.org/browse/XWIKI-20719 - (MISC) https://jira.xwiki.org/browse/XWIKI-20719 - Permissions Required
References (MISC) https://github.com/xwikisas/identity-oauth/security/advisories/GHSA-h2rm-29ch-wfmh - (MISC) https://github.com/xwikisas/identity-oauth/security/advisories/GHSA-h2rm-29ch-wfmh - Vendor Advisory
References (MISC) https://github.com/xwikisas/identity-oauth/blob/master/ui/src/main/resources/IdentityOAuth/LoginUIExtension.vm#L58 - (MISC) https://github.com/xwikisas/identity-oauth/blob/master/ui/src/main/resources/IdentityOAuth/LoginUIExtension.vm#L58 - Broken Link
References (MISC) https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6 - (MISC) https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6 - Patch
References (MISC) https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6#diff-2ab2e0716443d790d7d798320e4a45151661f4eca5440331f4a227b29c87c188 - (MISC) https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6#diff-2ab2e0716443d790d7d798320e4a45151661f4eca5440331f4a227b29c87c188 - Patch

16 Oct 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-16 21:15

Updated : 2024-11-21 08:26


NVD link : CVE-2023-45144

Mitre link : CVE-2023-45144

CVE.ORG link : CVE-2023-45144


JSON object : View

Products Affected

xwiki

  • oauth_identity
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')