CVE-2024-21648: XWiki has no right protection on rollback action

Published Jan 8, 2024
·
Updated

Impact

The rollback action is missing a right protection: it means that a user can rollback to a previous version of the page to gain rights they don't have anymore. This vulnerability impacts all version of XWiki since rollback action is available.

Patches

The problem has been patched in XWiki 14.10.16, 15.5.3 and 15.8-rc-1 by ensuring that the rights are checked before performing the rollback.

Workarounds

There's no workaround for this vulnerability, except paying attention to delete old versions of documents that could allow users to gain more rights.

References

JIRA ticket: https://jira.xwiki.org/browse/XWIKI-21257 Commit: 4de72875ca49602796165412741033bfdbf1e680

For more information

If you have any questions or comments about this advisory: Open an issue in Jira XWiki.org Email us at Security Mailing List

Other sources

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The rollback action is missing a right protection, a user can rollback to a previous version of the page to gain rights they don't have anymore. The problem has been patched in XWiki 14.10.17, 15.5.3 and 15.8-rc-1 by ensuring that the rights are checked before performing the rollback.

NVD

Affected Software

6 affected componentsFixes available
maven/org.xwiki.platform:xwiki-platform>=15.6-rc-1<15.8-rc-1
15.8-rc-1
maven/org.xwiki.platform:xwiki-platform>=15.0-rc-1<15.5.3
15.5.3
maven/org.xwiki.platform:xwiki-platform-oldcore>=1.0<14.10.17
14.10.17
XWiki xwiki<14.10.17
XWiki xwiki>=15.0<15.5.3
XWiki xwiki>=15.6<15.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.xwiki.platform:xwiki-platform to a version that resolves this vulnerability.

    Fixed in 15.8-rc-1
  2. Upgrade

    Upgrade maven/org.xwiki.platform:xwiki-platform to a version that resolves this vulnerability.

    Fixed in 15.5.3
  3. Upgrade

    Upgrade maven/org.xwiki.platform:xwiki-platform-oldcore to a version that resolves this vulnerability.

    Fixed in 14.10.17
  4. Upgrade

    Upgrade XWiki to a version that resolves this vulnerability.

    Fixed in 14.10.16
  5. Upgrade

    Upgrade XWiki to a version that resolves this vulnerability.

    Fixed in 15.5.3
  6. Upgrade

    Upgrade XWiki to a version that resolves this vulnerability.

    Fixed in 15.8-rc-1
  7. Compensating control

    Ensure old page versions that could allow users to gain more rights are deleted, since there is no workaround and the vulnerability can affect users via rollback to previous versions.

Event History

Jan 8, 2024
Advisory Published
04:25 PM
CVE Published
via MITRE·11:31 PM
Data Sourced
via MITRE·11:31 PM
DescriptionSeverityWeakness
Jan 9, 2024
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-21648?

CVE-2024-21648 is considered a high severity vulnerability due to its potential for unauthorized access through the rollback action.

2

How do I fix CVE-2024-21648?

To fix CVE-2024-21648, upgrade to XWiki version 15.8-rc-1, 15.5.3, or 14.10.17.

3

Which versions of XWiki are affected by CVE-2024-21648?

All versions of XWiki are affected by CVE-2024-21648 since the rollback functionality is available across them.

4

What impact does CVE-2024-21648 have on users?

CVE-2024-21648 allows users to gain access to rights they no longer have by rolling back to previous versions of pages.

5

Is there a workaround for CVE-2024-21648?

There is no official workaround for CVE-2024-21648; upgrading to the fixed versions is the recommended action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203