CVE-2023-45144: Remote code execution from login screen through unescaped URL parameter in OAuth Identity XWiki App

Published Oct 16, 2023
·
Updated

Impact

When login via the OAuth method, the identityOAuth parameters, sent in a GET request is vulnerable to XSS and XWiki syntax injection. This allows remote code execution via the groovy macro and thus affects the confidentiality, integrity and availability of the whole XWiki installation.

The vulnerability is in this part of the code.

Patches The issue has been fixed in Identity OAuth version 1.6 by https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6 . The fix is in the content of the IdentityOAuth/LoginUIExtension file

Workarounds There are no known workarounds besides upgrading.

References Are there any links users can visit to find out more?

Original report: https://jira.xwiki.org/browse/XWIKI-20719

Other sources

com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and XWiki syntax injection. This allows remote code execution via the groovy macro and thus affects the confidentiality, integrity and availability of the whole XWiki installation. The issue has been fixed in Identity OAuth version 1.6. There are no known workarounds for this vulnerability and users are advised to upgrade.

MITRE

Affected Software

2 affected componentsFixes available
maven/com.xwiki.identity-oauth:identity-oauth-ui>=1.0<1.6
1.6
XWiki OAuth Identity>=1.0<1.6

Event History

Oct 16, 2023
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness
Oct 17, 2023
Advisory Published
12:51 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the impact of CVE-2023-45144?

The vulnerability allows remote code execution via the groovy macro, affecting the confidentiality, integrity, and availability of the XWiki installation.

2

How does CVE-2023-45144 affect the XWiki installation?

CVE-2023-45144 allows an attacker to execute remote code through the groovy macro, compromising the confidentiality, integrity, and availability of the XWiki installation.

3

How can CVE-2023-45144 be exploited?

The vulnerability can be exploited by sending malicious identityOAuth parameters in a GET request when logging in via the OAuth method.

4

Which software versions are affected by CVE-2023-45144?

The vulnerability affects versions 1.0 to 1.6 of the com.xwiki.identity-oauth:identity-oauth-ui package in XWiki.

5

Is there a fix available for CVE-2023-45144?

Yes, updating the com.xwiki.identity-oauth:identity-oauth-ui package to version 1.6 or higher will fix the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203