XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed information includes for each modification of the page the time of the modification, the version number, the author of the modification (both username and displayed name) and the version comment. This information is exposed regardless of the rights setup, and even when the wiki is configured to be fully private. On a private wiki, this can be tested by accessing /xwiki/rest/wikis/xwiki/spaces/Main/pages/WebHome/history, if this shows the history of the main page then the installation is vulnerable. This has been patched in XWiki 15.10.9 and XWiki 16.3.0RC1.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Sep 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Xwiki xwiki
|
|
CPEs | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | |
Vendors & Products |
Xwiki xwiki
|
Tue, 10 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Xwiki
Xwiki xwiki-platform |
|
CPEs | cpe:2.3:a:xwiki:xwiki-platform:*:*:*:*:*:*:*:* | |
Vendors & Products |
Xwiki
Xwiki xwiki-platform |
|
Metrics |
ssvc
|
Tue, 10 Sep 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed information includes for each modification of the page the time of the modification, the version number, the author of the modification (both username and displayed name) and the version comment. This information is exposed regardless of the rights setup, and even when the wiki is configured to be fully private. On a private wiki, this can be tested by accessing /xwiki/rest/wikis/xwiki/spaces/Main/pages/WebHome/history, if this shows the history of the main page then the installation is vulnerable. This has been patched in XWiki 15.10.9 and XWiki 16.3.0RC1. | |
Title | XWiki Platform document history including authors of any page exposed to unauthorized actors | |
Weaknesses | CWE-359 CWE-862 |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-09-10T15:56:53.484Z
Updated: 2024-09-10T19:22:03.317Z
Reserved: 2024-09-02T16:00:02.422Z
Link: CVE-2024-45591
Vulnrichment
Updated: 2024-09-10T19:21:13.888Z
NVD
Status : Analyzed
Published: 2024-09-10T16:15:21.340
Modified: 2024-09-20T19:55:54.657
Link: CVE-2024-45591
Redhat
No data.