4.9

CVE-2022-41929

Exploit

Missing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcore

org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorrectly authorized user with only Script rights to enable or disable a user. This operation is meant to only be available for users with admin rights. This problem has been patched in XWiki 13.10.7, 14.4.2 and 14.5RC1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
XwikiXwiki Version > 11.7 < 13.10.7
XwikiXwiki Version > 14.0.0 < 14.4.2
XwikiXwiki Version11.7 Updaterc1
XwikiXwiki Version14.4.3
XwikiXwiki Version14.4.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.71% 0.487
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
security-advisories@github.com 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://github.com/xwiki/xwiki-platform/commit/0b732f2ef0224e2aaf10e2e1ef48dbd3fb6e10cd
Patch
Third Party Advisory
https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-2gj2-vj98-j2qq
Third Party Advisory
https://jira.xwiki.org/browse/XWIKI-19804
Patch
Vendor Advisory
Exploit
Issue Tracking