Improper Authorization Affecting org.xwiki.platform:xwiki-platform-oldcore package, versions [12.10.0,12.10.2) [12.0,12.6.7) [11.6,11.10.13)
Threat Intelligence
EPSS
0.22% (62nd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGXWIKIPLATFORM-1294538
- published 19 May 2021
- disclosed 18 May 2021
- credit Unknown
Introduced: 18 May 2021
CVE-2021-32620 Open this link in a new tabHow to fix?
Upgrade org.xwiki.platform:xwiki-platform-oldcore
to version 12.10.2, 12.6.7, 11.10.13 or higher.
Overview
org.xwiki.platform:xwiki-platform-oldcore is a generic wiki platform offering runtime services for applications built on top of it.
Affected versions of this package are vulnerable to Improper Authorization. A user disabled on a wiki using email verification for registration can re-activate himself by using the activation link provided for his registration.
References
CVSS Scores
version 3.1