Missing authorization in xwiki-platform
Moderate severity
GitHub Reviewed
Published
Feb 9, 2022
in
xwiki/xwiki-platform
•
Updated Feb 3, 2023
Package
Affected versions
< 12.10.6
>= 13.0, <= 13.1
Patched versions
12.10.6
13.2-rc-1
Description
Published by the National Vulnerability Database
Feb 9, 2022
Published to the GitHub Advisory Database
Feb 9, 2022
Reviewed
Feb 9, 2022
Last updated
Feb 3, 2023
Impact
Any user with edit right can copy the content of a page it does not have access to by using it as template of a new page.
Patches
It has been patched in XWiki 13.2CR1 and 12.10.6
Workarounds
There is no workaround beside patching.
References
https://jira.xwiki.org/browse/XWIKI-18430
For more information
If you have any questions or comments about this advisory:
References