QID 982350
QID 982350: Java (maven) Security Update for org.xwiki.commons:xwiki-commons-core (GHSA-76mp-659p-rw65)
Security update has been released for org.xwiki.commons:xwiki-commons-core to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A user disabled on a wiki using email verification for registration can re-activate himself by using the activation link provided for his registration.
Solution
The problem has been patched in the following versions of XWiki: 11.10.13, 12.6.7, 12.10.2, 13.0.Workaround:
It's possible to workaround the issue by resetting the `validkey` property of the disabled XWiki users. This can be done by editing the user profile with object editor.
It's possible to workaround the issue by resetting the `validkey` property of the disabled XWiki users. This can be done by editing the user profile with object editor.
Vendor References
- GHSA-76mp-659p-rw65 -
github.com/advisories/GHSA-76mp-659p-rw65
CVEs related to QID 982350
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-76mp-659p-rw65 | org.xwiki.commons:xwiki-commons-core |
|