QID 995604

Date Published: 2023-10-18

QID 995604: Java (Maven) Security Update for com.xwiki.identity-oauth:identity-oauth-ui (GHSA-h2rm-29ch-wfmh)

When login via the OAuth method, the identityOAuth parameters, sent in a GET request is vulnerable to XSS and XWiki syntax injection. This allows remote code execution via the groovy macro and thus affects the confidentiality, integrity and availability of the whole XWiki installation.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.6 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Github security advisory GHSA-h2rm-29ch-wfmh for updates and patch information.
    Vendor References

    CVEs related to QID 995604

    Software Advisories
    Advisory ID Software Component Link
    GHSA-h2rm-29ch-wfmh com.xwiki.identity-oauth:identity-oauth-ui URL Logo github.com/advisories/GHSA-h2rm-29ch-wfmh