Transmission of Private Resources into a New Sphere ('Resource Leak') Affecting org.xwiki.platform:xwiki-platform-livetable-ui package, versions [3.5-milestone-1,14.10.9)[15.0,15.3-rc-1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept
EPSS
0.12% (48th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGXWIKIPLATFORM-5808465
  • published28 Jul 2023
  • disclosed27 Jul 2023
  • creditIlie Andriuta

Introduced: 27 Jul 2023

CVE-2023-38509  (opens in a new tab)
CWE-402  (opens in a new tab)

How to fix?

Upgrade org.xwiki.platform:xwiki-platform-livetable-ui to version 14.10.9, 15.3-rc-1 or higher.

Overview

Affected versions of this package are vulnerable to Transmission of Private Resources into a New Sphere ('Resource Leak') due to exposing sensitive information when sorting e-mail addresses.

The mail obfuscation configuration was not fully taken into account and is was still possible by obfuscated emails.

CVSS Scores

version 3.1