logo

CVE-2021-32731 org.xwiki.platform:xwiki-platform-web

Package

Manager: maven
Name: org.xwiki.platform:xwiki-platform-web
Vulnerable Version: >=13.1 <13.2

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00171 pctl0.38871

Details

The reset password form reveal users email address ### Impact The reset password form reveals the email address of users just by giving their username. ### Patches The problem has been patched on XWiki 13.2RC1. ### Workarounds It's possible to manually modify the `resetpasswordinline.vm` to perform the changes made in https://github.com/xwiki/xwiki-platform/commit/0cf716250b3645a5974c80d8336dcdf885749dff#diff-14a3132e3986b1f5606dd13d9d8a8bb8634bec9932123c5e49e9604cfd850fc2 ### References https://jira.xwiki.org/browse/XWIKI-18400 ### For more information If you have any questions or comments about this advisory: * Open an issue in [Jira XWiki](https://jira.xiwki.org) * Email us at [Security ML](mailto:security@xwiki.org)

Metadata

Created: 2021-07-02T19:19:04Z
Modified: 2022-10-25T20:25:48Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/07/GHSA-h4m4-pgp4-whgm/GHSA-h4m4-pgp4-whgm.json
CWE IDs: ["CWE-200", "CWE-668"]
Alternative ID: GHSA-h4m4-pgp4-whgm
Finding: F017
Auto approve: 1