Missing Authorization Affecting org.xwiki.platform:xwiki-platform-attachment-api package, versions [,14.4.8)[14.5,14.10.4)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept
EPSS
0.1% (42nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGXWIKIPLATFORM-6036198
  • published26 Oct 2023
  • disclosed25 Oct 2023
  • creditUnknown

Introduced: 25 Oct 2023

CVE-2023-37910  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade org.xwiki.platform:xwiki-platform-attachment-api to version 14.4.8, 14.10.4 or higher.

Overview

org.xwiki.platform:xwiki-platform-attachment-api is a module for APIs related to attachments manipulation

Affected versions of this package are vulnerable to Missing Authorization. An attacker with edit access on any document can move any attachment of any other document to this attacker-controlled document, due to predictable naming schemes. This allows the attacker to access and possibly publish any attachment of which the name is known. The attachment is also deleted from the source document.

CVSS Scores

version 3.1