Skip to content

Missing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcore

Moderate
surli published GHSA-2gj2-vj98-j2qq Nov 21, 2022

Package

maven org.xwiki.platform:xwiki-platform-oldcore (Maven)

Affected versions

>= 11.7RC1

Patched versions

14.5RC1, 14.4.2, 13.10.7

Description

Impact

It's possible for a user with only Script rights to enable or disable a user: this operation should be only doable for users with admin rights.

Patches

This problem has been patched in XWiki 13.10.7, 14.4.2 and 14.5RC1.

Workarounds

There is no workaround other than upgrading the wiki, but note that this only impacts users with Script rights: administrator should take care which users have such right.

References

For more information

If you have any questions or comments about this advisory:

Severity

Moderate
4.9
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

CVE ID

CVE-2022-41929

Weaknesses