CVE-2023-35151: XWiki Platform may show email addresses in clear in REST results
Impact Any user can call a REST endpoint and obtain the obfuscated passwords (even when the mail obfuscation is activated).
For instance, by calling http://localhost:8080/xwiki/rest/wikis/xwiki/spaces/XWiki/pages/U1/objects/XWiki.XWikiUsers/0 when user U1 exists on wiki xwiki.
Patches The issue has been patched on XWiki 14.4.8, 14.10.6, and 15.1
Workarounds There is no known workaround. It is advised to upgrade to one of the patched versions.
References - https://jira.xwiki.org/browse/XWIKI-16138 - https://github.com/xwiki/xwiki-platform/commit/824cd742ecf5439971247da11bfe7e0ad2b10ede
For more information
If you have any questions or comments about this advisory: Open an issue in Jira XWiki.org Email us at Security Mailing List
Other sources
XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activated. The issue has been patched in XWiki 14.4.8, 14.10.6, and 15.1. There is no known workaround.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.xwiki.platform:xwiki-platform-rest-serverto a version that resolves this vulnerability.Fixed in 15.1 - Upgrade
Upgrade
maven/org.xwiki.platform:xwiki-platform-rest-serverto a version that resolves this vulnerability.Fixed in 14.10.6 - Upgrade
Upgrade
maven/org.xwiki.platform:xwiki-platform-rest-serverto a version that resolves this vulnerability.Fixed in 14.4.8 - Upgrade
Upgrade
XWikito a version that resolves this vulnerability.Fixed in 14.4.8 - Upgrade
Upgrade
XWikito a version that resolves this vulnerability.Fixed in 14.10.6 - Upgrade
Upgrade
XWikito a version that resolves this vulnerability.Fixed in 15.1
Event History
Frequently Asked Questions
What is CVE-2023-35151?
CVE-2023-35151 is a vulnerability in XWiki Platform where any user can call a REST endpoint and obtain obfuscated passwords, even when mail obfuscation is activated.
What is the severity of CVE-2023-35151?
The severity of CVE-2023-35151 is high, with a severity value of 7.5.
Which versions of XWiki Platform are affected by CVE-2023-35151?
The affected versions of XWiki Platform are 7.3-milestone-1 to 14.4.8, 14.10.6, and 15.1.
How can I fix CVE-2023-35151?
To fix CVE-2023-35151, update XWiki Platform to version 14.4.8, 14.10.6, or 15.1.
Where can I find more information about CVE-2023-35151?
More information about CVE-2023-35151 can be found in the references: [GitHub commit](https://github.com/xwiki/xwiki-platform/commit/824cd742ecf5439971247da11bfe7e0ad2b10ede), [GitHub security advisory](https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-8g9c-c9cm-9c56), [XWiki issue tracker](https://jira.xwiki.org/browse/XWIKI-16138).