Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2022-31167 | First vendor Publication | 2022-09-07 |
Vendor | Cve | Last vendor Modification | 2022-09-14 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N | |||
---|---|---|---|
Overall CVSS Score | 6.5 | ||
Base Score | 6.5 | Environmental Score | 6.5 |
impact SubScore | 3.6 | Temporal Score | 6.5 |
Exploitabality Sub Score | 2.8 | ||
Attack Vector | Network | Attack Complexity | Low |
Privileges Required | Low | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | None |
Integrity Impact | High | Availability Impact | None |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : | |||
---|---|---|---|
Cvss Base Score | N/A | Attack Range | N/A |
Cvss Impact Score | N/A | Attack Complexity | N/A |
Cvss Expoit Score | N/A | Authentication | N/A |
Calculate full CVSS 2.0 Vectors scores |
Detail
XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.10.11, 13.10.1, and 13.4.6, a bug in the security cache stores rules associated to document Page1.Page2 and space Page1.Page2 in the same cache entry. That means that it's possible to overwrite the rights of a space or a document by creating the page of the space with the same name and checking the right of the new one first so that they end up in the security cache and are used for the other too. The problem has been patched in XWiki 12.10.11, 13.10.1, and 13.4.6. There are no known workarounds. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31167 |
CPE : Common Platform Enumeration
Sources (Detail)
Source | Url |
---|---|
CONFIRM | https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-gg53-wf5x-r3r6 |
MISC | https://jira.xwiki.org/browse/XWIKI-14075 https://jira.xwiki.org/browse/XWIKI-18983 |
Alert History
Date | Informations |
---|---|
2024-09-07 02:29:32 |
|
2023-11-30 02:22:47 |
|
2023-11-03 02:29:33 |
|
2023-11-01 02:23:32 |
|
2023-09-30 13:19:46 |
|
2023-08-30 02:19:36 |
|
2023-07-01 02:16:13 |
|
2023-05-17 02:14:28 |
|
2023-05-02 02:15:27 |
|
2023-04-27 02:19:38 |
|
2023-04-26 02:18:20 |
|
2023-03-15 02:12:17 |
|
2023-03-14 02:12:32 |
|
2022-12-01 02:07:08 |
|
2022-09-15 21:27:19 |
|
2022-09-14 21:27:15 |
|
2022-09-07 21:27:12 |
|