Information exposure in xwiki-platform
Moderate severity
GitHub Reviewed
Published
Feb 9, 2022
in
xwiki/xwiki-platform
•
Updated Feb 3, 2023
Package
Affected versions
>= 13.5RC1, <= 13.5
>= 13.0.0, < 13.4.1
< 12.10.9
Patched versions
13.6RC1
13.4.1
12.10.9
Description
Published by the National Vulnerability Database
Feb 9, 2022
Published to the GitHub Advisory Database
Feb 9, 2022
Reviewed
Feb 9, 2022
Last updated
Feb 3, 2023
Impact
It's possible to guess if a user has an account on the wiki by using the "Forgot your password" form, even if the wiki is closed to guest users.
Patches
The problem has been patched on XWiki 12.10.9, 13.4.1 and 13.6RC1.
Workarounds
There's no easy workaround other than applying the upgrade.
References
https://jira.xwiki.org/browse/XWIKI-18787
For more information
If you have any questions or comments about this advisory:
References