CVE-2022-41935
Published on: Not Yet Published
Last Modified on: 11/30/2022 05:34:00 PM UTC
Certain versions of Xwiki from Xwiki contain the following vulnerability:
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users without the right to view documents can deduce their existence by repeated Livetable queries. The issue has been patched in XWiki 14.6RC1, 13.10.8, and 14.4.3, the response is not properly cleaned up of obfuscated entries. As a workaround, The patch for the document `XWiki.LiveTableResultsMacros` can be manually applied or a XAR archive of a patched version can be imported, on versions 12.10.11, 13.9-rc-1, and 13.4.4. There are no known workarounds for this issue.
- CVE-2022-41935 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
xwiki - xwiki-platform version >= 12.10.11, < 13.10.8
- Affected Vendor/Software:
xwiki - xwiki-platform version >= 14.0.0, < 14.4.3
CVSS3 Score: 4.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Loading... | jira.xwiki.org text/html |
![]() |
XWIKI-19999: Livetable sources filtering improvement · xwiki/[email protected] · GitHub | github.com text/html |
![]() |
Exposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-livetable-ui · Advisory · xwiki/xwiki-platform · GitHub | github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Xwiki | Xwiki | All | All | All | All |
Application | Xwiki | Xwiki | 14.4.4 | All | All | All |
Application | Xwiki | Xwiki | 14.4.5 | All | All | All |
- cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*:
- cpe:2.3:a:xwiki:xwiki:14.4.4:*:*:*:*:*:*:*:
- cpe:2.3:a:xwiki:xwiki:14.4.5:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-41935 | 2022-11-23 20:38:45 |