Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.xwiki.platform/xwiki-platform-oldcore
  4. ›
  5. GMS-2022-6934

GMS-2022-6934: Creation of new database tables through login form on PostgreSQL

November 21, 2022

Impact

It’s possible to make XWiki create many new schemas and fill them with tables just by using a crafted user identifier in the login form.

Patches

The problem has been patched in XWiki 13.10.8, 14.6RC1 and 14.4.2.

Workarounds

The only workarounds for this are:

  • use an authenticator which does interpret the login as a reference to a document
  • using a different database than PostgreSQL
  • upgrade XWiki

References

https://jira.xwiki.org/browse/XWIKI-19886

For more information

If you have any questions or comments about this advisory:

  • Open an issue in Jira XWiki.org
  • Email us at Security Mailing List

References

  • github.com/advisories/GHSA-4x5r-6v26-7j4v
  • github.com/xwiki/xwiki-platform/security/advisories/GHSA-4x5r-6v26-7j4v

Code Behaviors & Features

Detect and mitigate GMS-2022-6934 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 13.10.8, all versions starting from 14.0.0 before 14.4.2, all versions starting from 14.5.0 before 14.6-rc-1

Fixed versions

  • 13.10.8
  • 14.4.2
  • 14.6-rc-1

Solution

Upgrade to versions 13.10.8, 14.4.2, 14.6-rc-1 or above. *Note*: 14.6-rc-1 may be an unstable version. Use caution.

Source file

maven/org.xwiki.platform/xwiki-platform-oldcore/GMS-2022-6934.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:44 +0000.