Skip to content

Privilege escalation (PR)/RCE from account through class sheet

Critical
tmortagne published GHSA-36fm-j33w-c25f May 9, 2023

Package

maven org.xwiki.platform:xwiki-platform-class-ui (Maven)

Affected versions

3.3-milestone-3

Patched versions

14.10.4, 15.0-rc-1

Description

Impact

It's possible for a user to execute anything with the right of the author of the XWiki.ClassSheet document.

Steps to Reproduce:

  1. Edit your user profile with the object editor and add an object of type DocumentSheetBinding with value Default Class Sheet
  2. Edit your user profile with the wiki editor and add the syntax {{async}}{{groovy}}println("Hello " + "from groovy!"){{/groovy}}{{/async}}
  3. Click "Save & View"

Expected result:

An error is displayed as the user doesn't have the right to execute the Groovy macro.

Actual result:

The text "Hello from groovy!" is displayed at the top of the document.

Patches

This has been patched in XWiki 15.0-rc-1 and 14.10.4.

Workarounds

There are no known workarounds for it.

References

https://jira.xwiki.org/browse/XWIKI-20566
de72760

For more information

If you have any questions or comments about this advisory:

Severity

Critical
9.9
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVE ID

CVE-2023-32069

Weaknesses