Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2025-6735 | XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesn't have view rights on them. It's particularly true if the entire wiki is protected with "Prevent unregistered user to view pages": the endpoint would still list the pages of the wiki, though only for the main wiki. The problem has been patched in XWiki 15.10.14, 16.4.6, 16.10.0RC1. In those versions the endpoint can still be requested but the result is filtered out based on pages rights. | 
  Github GHSA | 
                GHSA-22q5-9phm-744v | XWiki allows unregistered users to access private pages information through REST endpoint | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 30 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Xwiki
         Xwiki xwiki  | 
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Xwiki
         Xwiki xwiki  | 
|
| Metrics | 
        
        cvssV3_1
         
  | 
Wed, 19 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Wed, 19 Mar 2025 17:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesn't have view rights on them. It's particularly true if the entire wiki is protected with "Prevent unregistered user to view pages": the endpoint would still list the pages of the wiki, though only for the main wiki. The problem has been patched in XWiki 15.10.14, 16.4.6, 16.10.0RC1. In those versions the endpoint can still be requested but the result is filtered out based on pages rights. | |
| Title | XWiki allows unregistered users to access private pages information through REST endpoint | |
| Weaknesses | CWE-402 | |
| References | 
         | 
        
  | 
| Metrics | 
        
        cvssV4_0
         
  | 
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-19T19:25:43.966Z
Reserved: 2025-03-12T13:42:22.136Z
Link: CVE-2025-29925
Updated: 2025-03-19T19:25:35.295Z
Status : Analyzed
Published: 2025-03-19T18:15:25.300
Modified: 2025-04-30T15:57:32.057
Link: CVE-2025-29925
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD
 Github GHSA