CVE-2023-34467: XWiki Platform may retrieve email addresses of all users
Impact The mail obfuscation configuration was not fully taken into account and while the mail displayed to the end user was obfuscated: - the rest response was also containing the mail unobfuscated - user were able to filter and sort on the unobfuscated (allowing to infer the mail content)
The consequence was the possibility to retrieve the email addresses of all users even when obfuscated.
See https://jira.xwiki.org/browse/XWIKI-20333 for the reproduction steps.
Patches This has been patched in XWiki 14.10.4, XWiki 14.4.8, and XWiki 15.0-rc-1.
Workarounds The workaround is to modify the page XWiki.LiveTableResultsMacros following this patch.
References
https://jira.xwiki.org/browse/XWIKI-20333
For more information
If you have any questions or comments about this advisory:
Open an issue in Jira XWiki.org Email us at Security Mailing List
Attribution
This vulnerability has been reported on Intigriti by @floerer
Other sources
XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail displayed to the end user was obfuscated, the rest response was also containing the mail unobfuscated and users were able to filter and sort on the unobfuscated, allowing them to infer the mail content. The consequence was the possibility to retrieve the email addresses of all users even when obfuscated. This has been patched in XWiki 14.4.8, 14.10.4, and 15.0-rc-1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.xwiki.platform:xwiki-platform-livetable-uito a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
maven/org.xwiki.platform:xwiki-platform-livetable-uito a version that resolves this vulnerability.Fixed in 14.4.8 - Upgrade
Upgrade
XWiki Platformto a version that resolves this vulnerability.Fixed in 14.4.8 - Upgrade
Upgrade
XWiki Platformto a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
XWiki Platformto a version that resolves this vulnerability.Fixed in 15.0-rc-1 - Configuration
For installations in the vulnerable range (starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1), modify the XWiki page XWiki.LiveTableResultsMacros according to the referenced patch to ensure the mail obfuscation configuration is fully taken into account.
XWiki.LiveTableResultsMacros mail obfuscation handling in LiveTable results = apply the workaround by modifying the page XWiki.LiveTableResultsMacros as described in the referenced patch (commit diff 5a739e5865b1f1ad9d79b724791be51b0095a0170cc078911c940478b13b949a)
Event History
Frequently Asked Questions
What is the vulnerability ID for this XWiki Platform vulnerability?
The vulnerability ID for this XWiki Platform vulnerability is CVE-2023-34467.
What is the severity of CVE-2023-34467?
The severity of CVE-2023-34467 is high with a score of 7.5.
What is the affected software?
The affected software is XWiki Platform versions 3.5-milestone-1 to 14.4.8, 14.10.4, and 15.0-rc-1.
How does the vulnerability affect XWiki Platform?
The vulnerability affects XWiki Platform by not fully taking into account the mail obfuscation configuration, allowing the mail response to contain unobfuscated information.
Is there a fix available for CVE-2023-34467?
Yes, a fix is available. It is recommended to update XWiki Platform to versions 14.4.8, 14.10.4, or 15.0-rc-1.