Lucene search

K
cveGitHub_MCVE-2023-50719
HistoryDec 15, 2023 - 7:15 p.m.

CVE-2023-50719

2023-12-1519:15:09
CWE-312
CWE-359
CWE-200
GitHub_M
web.nvd.nist.gov
17
xwiki
platform
vulnerability
password hashes
solr-based search
disclosure
user profiles
api keys
plaintext disclosure
patch

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.361

Percentile

97.2%

XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respective user profiles. By default, all user profiles are public. This vulnerability also affects any configurations used by extensions that contain passwords like API keys that are viewable for the attacker. Normally, such passwords aren’t accessible but this vulnerability would disclose them as plain text. This has been patched in XWiki 14.10.15, 15.5.2 and 15.7RC1. There are no known workarounds for this vulnerability.

Affected configurations

Nvd
Vulners
Node
xwikixwikiRange7.314.10.5
OR
xwikixwikiRange15.015.5.2
OR
xwikixwikiMatch7.2milestone2
OR
xwikixwikiMatch7.2milestone3
OR
xwikixwikiMatch15.6-
OR
xwikixwikiMatch15.6rc1
OR
xwikixwikiMatch15.7rc1
VendorProductVersionCPE
xwikixwiki*cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
xwikixwiki7.2cpe:2.3:a:xwiki:xwiki:7.2:milestone2:*:*:*:*:*:*
xwikixwiki7.2cpe:2.3:a:xwiki:xwiki:7.2:milestone3:*:*:*:*:*:*
xwikixwiki15.6cpe:2.3:a:xwiki:xwiki:15.6:-:*:*:*:*:*:*
xwikixwiki15.6cpe:2.3:a:xwiki:xwiki:15.6:rc1:*:*:*:*:*:*
xwikixwiki15.7cpe:2.3:a:xwiki:xwiki:15.7:rc1:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "xwiki",
    "product": "xwiki-platform",
    "versions": [
      {
        "version": ">= 7.2-milestone-2, < 14.10.15",
        "status": "affected"
      },
      {
        "version": ">= 15.0-rc-1, < 15.5.2",
        "status": "affected"
      },
      {
        "version": ">= 15.6-rc-1, < 15.7-rc-1",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.361

Percentile

97.2%

Related for CVE-2023-50719