Skip to content

It's possible to read any file from the WAR with just SCRIPT right through $xwiki.invokeServletAndReturnAsString

Moderate
tmortagne published GHSA-2jhm-qp48-hv5j Feb 9, 2022

Package

maven org.xwiki.platform:xwiki-platform-oldcore (Maven)

Affected versions

< 12.10.9, < 13.4.3, < 13.7-rc-1

Patched versions

12.10.9, 13.4.3, 13.7-rc-1

Description

Impact

Any user with SCRIPT right (EDIT right before XWiki 7.4) can read any file located in the XWiki WAR (for example xwiki.cfg and xwiki.properties) through XWiki#invokeServletAndReturnAsString:

$xwiki.invokeServletAndReturnAsString("/WEB-INF/xwiki.cfg")

Patches

It has been patched in XWiki versions 12.10.9, 13.4.3 and 13.7-rc-1.

Workarounds

The only workaround is to give SCRIPT right only to trusted users.

References

https://jira.xwiki.org/browse/XWIKI-18870

For more information

If you have any questions or comments about this advisory:

Severity

Moderate
6.0
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
High
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H

CVE ID

CVE-2022-23621