logo

CVE-2022-41930 org.xwiki.platform:xwiki-platform-user-profile-ui

Package

Manager: maven
Name: org.xwiki.platform:xwiki-platform-user-profile-ui
Vulnerable Version: >=12.4 <13.10.7 || >=14.0.0 <14.4.2

Severity

Level: Critical

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00439 pctl0.62261

Details

Missing Authorization to enable or disable users in org.xwiki.platform:xwiki-platform-user-profile-ui ### Impact Any user (logged in or not) with access to the page XWiki.XWikiUserProfileSheet can enable or disable any user profile. This might allow to a disabled user to re-enable themselves, or to an attacker to disable any user of the wiki. ### Patches The problem has been patched in XWiki 13.10.7, 14.5RC1 and 14.4.2. ### Workarounds The problem can be patched immediately by editing the page `XWiki.XWikiUserProfileSheet` in the wiki and by performing the changes contained in https://github.com/xwiki/xwiki-platform/commit/5be1cc0adf917bf10899c47723fa451e950271fa. ### References * https://github.com/xwiki/xwiki-platform/commit/5be1cc0adf917bf10899c47723fa451e950271fa * https://jira.xwiki.org/browse/XWIKI-19792 ### For more information If you have any questions or comments about this advisory: * Open an issue in [JIRA](https://jira.xwiki.org) * Email us at [security ML](mailto:security@xwiki.org)

Metadata

Created: 2022-11-21T22:35:39Z
Modified: 2025-01-22T17:43:50Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-p5v9-g8w8-5q4v/GHSA-p5v9-g8w8-5q4v.json
CWE IDs: ["CWE-862"]
Alternative ID: GHSA-p5v9-g8w8-5q4v
Finding: F039
Auto approve: 1