CVE-2024-55876: XWiki's scheduler in subwiki allows scheduling operations for any main wiki user
Impact Any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki without any special right, view the document Scheduler.WebHome in a subwiki. Then, click on any operation (e.g., Trigger) on any job. If the operation is successful, then the instance is vulnerable.
Patches This has been patched in XWiki 15.10.9 and 16.3.0.
Workarounds If you have subwikis where the Job Scheduler is enabled, you can edit the objects on Scheduler.WebPreferences to match https://github.com/xwiki/xwiki-platform/commit/54bcc5a7a2e440cc591b91eece9c13dc0c487331#diff-8e274bd0065e319a34090339de6dfe56193144d15fd71c52c1be7272254728b4.
References https://jira.xwiki.org/browse/XWIKI-21663 https://github.com/xwiki/xwiki-platform/commit/54bcc5a7a2e440cc591b91eece9c13dc0c487331
For more information If you have any questions or comments about this advisory: Open an issue in Jira XWiki.org Email us at Security Mailing List
Other sources
XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki without any special right, view the document Scheduler.WebHome in a subwiki. Then, click on any operation (e.g., Trigger) on any job. If the operation is successful, then the instance is vulnerable. This has been patched in XWiki 15.10.9 and 16.3.0. As a workaround, those who have subwikis where the Job Scheduler is enabled can edit the objects on Scheduler.WebPreferences to match the patch.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55876?
CVE-2024-55876 is considered a significant vulnerability due to its potential impact on user operations in subwikis.
How do I fix CVE-2024-55876?
To fix CVE-2024-55876, upgrade to version 16.3.0 or 15.10.9 of the xwiki-platform-scheduler-ui package.
Who is affected by CVE-2024-55876?
Any user with an account on the main wiki is affected by CVE-2024-55876 when running scheduling operations on subwikis.
Can CVE-2024-55876 be exploited without special rights?
Yes, CVE-2024-55876 can be exploited by users without any special rights on the main wiki.
What operation can be triggered by exploiting CVE-2024-55876?
Exploiting CVE-2024-55876 allows users to trigger operations, such as scheduling jobs, on subwikis.