Lucene search

K
jvnJapan Vulnerability NotesJVN:48194211
HistoryJul 28, 2020 - 12:00 a.m.

JVN#48194211: Multiple vulnerabilities in KonaWiki2 and KonaWiki3

2020-07-2800:00:00
Japan Vulnerability Notes
jvn.jp
42
konawiki
vulnerabilities
cross-site scripting
path traversal
cve-2020-5612
cve-2020-5613
cve-2020-5614
update software
products affected

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.002

Percentile

55.6%

KonaWiki2 and KonaWiki3 are lightweight wiki clones that support Japanese wiki notation. KonaWiki2 and KonaWiki3 contain multiple vulnerabilities listed below.

KonaWiki2

Cross-site Scripting (CWE-79) - CVE-2020-5612

Version Vector Score
CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Base Score: 6.1
CVSS v2 AV:N/AC:M/Au:N/C:N/I:P/A:N Base Score: 4.3

KonaWiki3 Cross-site Scripting (CWE-79) - CVE-2020-5613

Version Vector Score
CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Base Score: 6.1
CVSS v2 AV:N/AC:M/Au:N/C:N/I:P/A:N Base Score: 4.3

Path Traversal (CWE-22) - CVE-2020-5614

Version Vector Score
CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score: 5.3
CVSS v2 AV:N/AC:L/Au:N/C:P/I:N/A:N Base Score: 5.0

Impact

  • Because the sanitizing process is not performed properly, an arbitrary web script is executed on the web browser of the user who accesses a specially crafted URL. - CVE-2020-5612, CVE-2020-5613
  • Inadequate query checking allows unauthorized disclosure of information stored above the target directory published as a site by a remote attacker. - CVE-2020-5614

Solution

Update the software
Update the software to the latest version according to the information provided by the developer.

  • KonaWiki2.2.1
  • KonaWiki3.1.1

Products Affected

  • KonaWiki2.2.0 and earlier
  • KonaWiki3.1.0 and earlier

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.002

Percentile

55.6%

Related for JVN:48194211