Skip to content

Information exposure in xwiki-platform

Moderate severity GitHub Reviewed Published Feb 9, 2022 in xwiki/xwiki-platform • Updated Feb 3, 2023

Package

maven org.xwiki.platform:xwiki-platform-web (Maven)

Affected versions

>= 13.5RC1, <= 13.5
>= 13.0.0, < 13.4.1
< 12.10.9

Patched versions

13.6RC1
13.4.1
12.10.9

Description

Impact

It's possible to guess if a user has an account on the wiki by using the "Forgot your password" form, even if the wiki is closed to guest users.

Patches

The problem has been patched on XWiki 12.10.9, 13.4.1 and 13.6RC1.

Workarounds

There's no easy workaround other than applying the upgrade.

References

https://jira.xwiki.org/browse/XWIKI-18787

For more information

If you have any questions or comments about this advisory:

References

@tmortagne tmortagne published to xwiki/xwiki-platform Feb 9, 2022
Published by the National Vulnerability Database Feb 9, 2022
Published to the GitHub Advisory Database Feb 9, 2022
Reviewed Feb 9, 2022
Last updated Feb 3, 2023

Severity

Moderate
5.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE ID

CVE-2022-23619

GHSA ID

GHSA-35fg-hjcr-j65f

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.