Lucene search

K
nvd[email protected]NVD:CVE-2023-50719
HistoryDec 15, 2023 - 7:15 p.m.

CVE-2023-50719

2023-12-1519:15:09
CWE-200
CWE-359
CWE-312
web.nvd.nist.gov
4
xwiki
platform
vulnerability
password hashes
solr
search
user profiles
configurations
extensions
plain text
patch

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.361

Percentile

97.2%

XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respective user profiles. By default, all user profiles are public. This vulnerability also affects any configurations used by extensions that contain passwords like API keys that are viewable for the attacker. Normally, such passwords aren’t accessible but this vulnerability would disclose them as plain text. This has been patched in XWiki 14.10.15, 15.5.2 and 15.7RC1. There are no known workarounds for this vulnerability.

Affected configurations

Nvd
Node
xwikixwikiRange7.314.10.5
OR
xwikixwikiRange15.015.5.2
OR
xwikixwikiMatch7.2milestone2
OR
xwikixwikiMatch7.2milestone3
OR
xwikixwikiMatch15.6-
OR
xwikixwikiMatch15.6rc1
OR
xwikixwikiMatch15.7rc1
VendorProductVersionCPE
xwikixwiki*cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*
xwikixwiki7.2cpe:2.3:a:xwiki:xwiki:7.2:milestone2:*:*:*:*:*:*
xwikixwiki7.2cpe:2.3:a:xwiki:xwiki:7.2:milestone3:*:*:*:*:*:*
xwikixwiki15.6cpe:2.3:a:xwiki:xwiki:15.6:-:*:*:*:*:*:*
xwikixwiki15.6cpe:2.3:a:xwiki:xwiki:15.6:rc1:*:*:*:*:*:*
xwikixwiki15.7cpe:2.3:a:xwiki:xwiki:15.7:rc1:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.361

Percentile

97.2%

Related for NVD:CVE-2023-50719