First published: Fri Jun 23 2023(Updated: )
XWiki Platform is a generic wiki platform. Starting in version 11.8-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.2, `Mail.MailConfig` can be edited by any logged-in user by default. Consequently, they can change the mail obfuscation configuration and view and edit the mail sending configuration, including the smtp domain name and credentials. The problem has been patched in XWiki 14.4.8, 14.10.6, and 15.1. As a workaround, the rights of the `Mail.MailConfig` page can be manually updated so that only a set of trusted users can view, edit and delete it (e.g., the `XWiki.XWikiAdminGroup` group).
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xwiki Xwiki | >=11.8.1<14.4.8 | |
Xwiki Xwiki | >=14.10<14.10.6 | |
Xwiki Xwiki | =11.8-milestone1 | |
Xwiki Xwiki | =15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34465 is a vulnerability in XWiki Platform where the `Mail.MailConfig` can be edited by any logged-in user, allowing them to change mail obfuscation configuration and view and edit mail sending configuration.
CVE-2023-34465 has a severity score of 8.1, which is considered critical.
Versions 11.8-rc-1 to 14.4.8, 14.10.6, and 15.2 of XWiki Platform are affected by CVE-2023-34465.
To fix CVE-2023-34465, you should upgrade your XWiki Platform to versions 14.4.8, 14.10.6, or 15.2, which contain the necessary security patches.
CWE-269 is a Common Weakness Enumeration identifier that refers to the category of Improper Privilege Management vulnerabilities.