GMS-2022-6934: Creation of new database tables through login form on PostgreSQL
Impact
It’s possible to make XWiki create many new schemas and fill them with tables just by using a crafted user identifier in the login form.
Patches
The problem has been patched in XWiki 13.10.8, 14.6RC1 and 14.4.2.
Workarounds
The only workarounds for this are:
- use an authenticator which does interpret the login as a reference to a document
- using a different database than PostgreSQL
- upgrade XWiki
References
https://jira.xwiki.org/browse/XWIKI-19886
For more information
If you have any questions or comments about this advisory:
- Open an issue in Jira XWiki.org
- Email us at Security Mailing List
References
Detect and mitigate GMS-2022-6934 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →