org.xwiki.platform:xwiki-platform-security-authentication-default XSS with authenticate endpoints
Moderate severity
GitHub Reviewed
Published
Apr 12, 2023
in
xwiki/xwiki-platform
•
Updated Apr 26, 2023
Package
Affected versions
>= 13.10.8, < 13.10.11
>= 14.4.3, < 14.4.7
>= 14.6, < 14.10
Patched versions
13.10.11
14.4.7
14.10
Description
Published to the GitHub Advisory Database
Apr 12, 2023
Reviewed
Apr 12, 2023
Published by the National Vulnerability Database
Apr 16, 2023
Last updated
Apr 26, 2023
Impact
It was possible to inject some code using the URL of authenticate endpoints, e.g.:
This vulnerability was present in recent versions of XWiki:
Patches
This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.
Workarounds
There is no easy workaround except to upgrade.
References
For more information
If you have any questions or comments about this advisory:
References