CVE-2023-26478

xwiki contains Exposed Dangerous Method or Function in maven/org.xwiki.platform/xwiki-platform-store-filesystem-oldcore

Identifiers

GHSA-8692-g6g9-gm5p, CVE-2023-26478

Package Slug

maven/org.xwiki.platform/xwiki-platform-store-filesystem-oldcore

Vulnerability

xwiki contains Exposed Dangerous Method or Function

Description

XWiki Platform is a generic wiki platform. Starting in version 14.3-rc-1, org.xwiki.store.script.TemporaryAttachmentsScriptService#uploadTemporaryAttachment returns an instance of com.xpn.xwiki.doc.XWikiAttachment. This class is not supported to be exposed to users without the programing right. com.xpn.xwiki.api.Attachment should be used instead and takes case of checking the user's rights before performing dangerous operations. This has been patched in versions 14.9-rc-1 and 14.4.6. There are no known workarounds for this issue.

Affected Versions

All versions starting from 14.3-rc-1 before 14.4.6, all versions starting from 14.5 before 14.9-rc-1

Solution

Upgrade to versions 14.4.6, 14.9-rc-1 or above. Note: 14.9-rc-1 may be an unstable version. Use caution.

Last Modified

2023-03-06

source