QID 983809

QID 983809: Java (maven) Security Update for org.xwiki.platform:xwiki-platform-administration-ui (GHSA-v9j2-q4q5-cxh4)

Security update has been released for org.xwiki.platform:xwiki-platform-administration-ui to fix the vulnerability. Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

It's possible for forge an URL that, when accessed by an admin, will reset the password of any user in XWiki.

  • CVSS V3 rated as Medium - 5.7 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    The problem has been patched in XWiki 12.10.5, 13.2RC1.Workaround:
    It's possible to apply the patch manually by modifying the `register_macros.vm` template like in https://github.com/xwiki/xwiki-platform/commit/0a36dbcc5421d450366580217a47cc44d32f7257.
    Vendor References

    CVEs related to QID 983809

    Software Advisories
    Advisory ID Software Component Link
    GHSA-v9j2-q4q5-cxh4 org.xwiki.platform:xwiki-platform-administration-ui URL Logo github.com/advisories/GHSA-v9j2-q4q5-cxh4