XWiki Platform is a generic wiki platform. Prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the email addresses of users even when obfuscation of email addresses is enabled. To demonstrate the vulnerability, search for `objcontent:email*` using XWiki's regular search interface. This has been fixed in XWiki 14.10.15, 15.5.2 and 15.7RC1 by not indexing email address properties when obfuscation is enabled. There are no known workarounds for this vulnerability.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-12-15T19:02:35.372Z

Updated: 2024-08-02T22:16:47.165Z

Reserved: 2023-12-11T17:53:36.030Z

Link: CVE-2023-50720

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-12-15T19:15:09.463

Modified: 2023-12-19T20:52:05.350

Link: CVE-2023-50720

cve-icon Redhat

No data.