xwiki xwiki 跨站请求伪造(csrf)

admin 2023-11-30 09:16:57 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
中危 xwiki xwiki 跨站请求伪造(csrf)

CVE编号

CVE-2021-32732

利用情况

暂无

补丁情况

官方补丁

披露时间

2022-02-05
漏洞描述
### Impact It's possible to know if a user has or not an account in a wiki related to an email address, and which username(s) is actually tied to that email by forging a request to the Forgot username page. Note that since this page does not have a CSRF check it's quite easy to perform a lot of those requests. ### Patches This issue has been patched in XWiki 12.10.5 and 13.2RC1. Two different patches are provided: - a first one to fix the CSRF problem - a more complex one that now relies on sending an email for the Forgot username process. ### Workarounds It's possible to fix the problem without uprading by editing the ForgotUsername page in version below 13.x, to use the following code: https://github.com/xwiki/xwiki-platform/blob/69548c0320cbd772540cf4668743e69f879812cf/xwiki-platform-core/xwiki-platform-administration/xwiki-platform-administration-ui/src/main/resources/XWiki/ForgotUsername.xml#L39-L123 In version after 13.x it's also possible to edit manually the forgotusername.vm file, but it's really encouraged to upgrade the version here. ### References * https://jira.xwiki.org/browse/XWIKI-18384 * https://jira.xwiki.org/browse/XWIKI-18408 ### For more information If you have any questions or comments about this advisory: * Open an issue in [Jira XWiki](https://jira.xwiki.org) * Email us at [security ML](mailto:[email protected])
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://github.com/xwiki/xwiki-platform/commit/69548c0320cbd772540cf4668743e6...
https://github.com/xwiki/xwiki-platform/commit/f0440dfcbba705e03f7565cd88893d...
https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-vh5c-jqfg-mhrh
https://jira.xwiki.org/browse/XWIKI-18384
https://jira.xwiki.org/browse/XWIKI-18408
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 xwiki xwiki * Up to (excluding) 12.10.5
运行在以下环境
应用 xwiki xwiki 13.0 -
运行在以下环境
应用 xwiki xwiki 13.1 -
阿里云评分 6.1
  • 攻击路径 本地
  • 攻击复杂度 困难
  • 权限要求 普通权限
  • 影响范围 有限影响
  • EXP成熟度 未验证
  • 补丁情况 官方补丁
  • 数据保密性 无影响
  • 数据完整性 无影响
  • 服务器危害 无影响
  • 全网数量 N/A
CWE-ID 漏洞类型
CWE-352 跨站请求伪造(CSRF)
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0