CVE-2022-41936

CVSS V2 None CVSS V3 None
Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modifications` rest endpoint does not filter out entries according to the user's rights. Therefore, information hidden from unauthorized users are exposed though the `modifications` rest endpoint (comments and page names etc). Users should upgrade to XWiki 14.6+, 14.4.3+, or 13.10.8+. Older versions have not been patched. There are no known workarounds.
Overview
  • CVE ID
  • CVE-2022-41936
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-11-22T01:15:34
  • Last Modified Date
  • 2022-11-28T14:37:41
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* 1 OR 8.1 13.10.8
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* 1 OR 14.0 14.4.3
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* 1 OR 14.5 14.6
History
Created Old Value New Value Data Type Notes
2022-11-22 02:00:11 Added to TrackCVE
2022-12-07 17:58:27 2022-11-22T01:15Z 2022-11-22T01:15:34 CVE Published Date updated
2022-12-07 17:58:27 2022-11-28T14:37:41 CVE Modified Date updated
2022-12-07 17:58:27 Analyzed Vulnerability Status updated
2022-12-07 17:58:29 CPE Information updated