Exposure of Private Personal Information to an Unauthorized Actor Affecting org.xwiki.platform:xwiki-platform-rest-server package, versions [,15.10.9)[16.0.0-rc-1,16.3.0-rc-1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
82.07% (100th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGXWIKIPLATFORM-7926870
  • published11 Sept 2024
  • disclosed10 Sept 2024
  • creditXiqinger

Introduced: 10 Sep 2024

CVE-2024-45591  (opens in a new tab)
CWE-359  (opens in a new tab)

How to fix?

Upgrade org.xwiki.platform:xwiki-platform-rest-server to version 15.10.9, 16.3.0-rc-1 or higher.

Overview

Affected versions of this package are vulnerable to Exposure of Private Personal Information to an Unauthorized Actor via the REST API endpoint /xwiki/rest/wikis/xwiki/spaces/Main/pages/WebHome/history. An attacker can access the modification history of any page, including modification times, version numbers and author details, by knowing the name of the page.

Note:

This exposure occurs regardless of the configured access rights or privacy settings of the wiki.

PoC

  1. Make your wiki fully private

  2. Log out

  3. Open /xwiki/rest/wikis/xwiki/spaces/Main/pages/WebHome/history and /xwiki/rest/wikis/xwiki/spaces/Main/pages/WebHome/translations/de/history on your XWiki installation.

CVSS Base Scores

version 4.0
version 3.1