CVE-2022-41930: org.xwiki.platform:xwiki-platform-user-profile-ui missing authorization to enable or disable users
Impact
Any user (logged in or not) with access to the page XWiki.XWikiUserProfileSheet can enable or disable any user profile. This might allow to a disabled user to re-enable themselves, or to an attacker to disable any user of the wiki.
Patches
The problem has been patched in XWiki 13.10.7, 14.5RC1 and 14.4.2.
Workarounds
The problem can be patched immediately by editing the page XWiki.XWikiUserProfileSheet in the wiki and by performing the changes contained in https://github.com/xwiki/xwiki-platform/commit/5be1cc0adf917bf10899c47723fa451e950271fa.
References
https://github.com/xwiki/xwiki-platform/commit/5be1cc0adf917bf10899c47723fa451e950271fa https://jira.xwiki.org/browse/XWIKI-19792
For more information If you have any questions or comments about this advisory: Open an issue in JIRA Email us at security ML
Other sources
org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged in or not) with access to the page XWiki.XWikiUserProfileSheet can enable or disable any user profile. This might allow to a disabled user to re-enable themselves, or to an attacker to disable any user of the wiki. The problem has been patched in XWiki 13.10.7, 14.5RC1 and 14.4.2. Workarounds: The problem can be patched immediately by editing the page XWiki.XWikiUserProfileSheet in the wiki and by performing the changes contained in https://github.com/xwiki/xwiki-platform/commit/5be1cc0adf917bf10899c47723fa451e950271fa.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.xwiki.platform:xwiki-platform-user-profile-uito a version that resolves this vulnerability.Fixed in 14.4.2 - Upgrade
Upgrade
maven/org.xwiki.platform:xwiki-platform-user-profile-uito a version that resolves this vulnerability.Fixed in 13.10.7 - Upgrade
Upgrade
XWikito a version that resolves this vulnerability.Fixed in 13.10.7 - Upgrade
Upgrade
XWikito a version that resolves this vulnerability.Fixed in 14.5RC1 - Upgrade
Upgrade
XWikito a version that resolves this vulnerability.Fixed in 14.4.2 - Configuration
Patch immediately by editing the page `XWiki.XWikiUserProfileSheet` in the wiki and applying the changes from commit `5be1cc0adf917bf10899c47723fa451e950271fa`.
XWiki `XWiki.XWikiUserProfileSheet` User profile enable/disable authorization = Apply the changes contained in commit 5be1cc0adf917bf10899c47723fa451e950271fa to prevent unauthorized enable/disable via the sheet
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41930?
CVE-2022-41930 is a medium severity vulnerability that allows unauthorized users to enable or disable any user profile.
How do I fix CVE-2022-41930?
To fix CVE-2022-41930, update the XWiki platform to version 14.4.3 or later, or 13.10.7 or later.
Who is affected by CVE-2022-41930?
Any user who has access to the XWiki.XWikiUserProfileSheet page may be affected by CVE-2022-41930.
What versions of XWiki are vulnerable to CVE-2022-41930?
XWiki versions from 12.4 to 14.4.2 are vulnerable to CVE-2022-41930.
What can an attacker do with CVE-2022-41930?
An attacker can potentially disable any user of the wiki or re-enable a disabled user profile due to CVE-2022-41930.