Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.xwiki.platform/xwiki-platform-security
  4. ›
  5. CVE-2022-31167

CVE-2022-31167: Missing Authorization

September 20, 2022

XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.10.11, 13.10.1, and 13.4.6, a bug in the security cache stores rules associated to document Page1.Page2 and space Page1.Page2 in the same cache entry. That means that it’s possible to overwrite the rights of a space or a document by creating the page of the space with the same name and checking the right of the new one first so that they end up in the security cache and are used for the other too. The problem has been patched in XWiki 12.10.11, 13.10.1, and 13.4.6. There are no known workarounds.

References

  • github.com/advisories/GHSA-gg53-wf5x-r3r6
  • github.com/xwiki/xwiki-platform/security/advisories/GHSA-gg53-wf5x-r3r6
  • jira.xwiki.org/browse/XWIKI-14075
  • jira.xwiki.org/browse/XWIKI-18983
  • nvd.nist.gov/vuln/detail/CVE-2022-31167

Code Behaviors & Features

Detect and mitigate CVE-2022-31167 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 5.0 before 12.10.11, all versions starting from 13.0 before 13.4.6, all versions starting from 13.10 before 13.10.1

Fixed versions

  • 12.10.11
  • 13.4.6
  • 13.10.1

Solution

Upgrade to versions 12.10.11, 13.4.6, 13.10.1 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-862: Missing Authorization

Source file

maven/org.xwiki.platform/xwiki-platform-security/CVE-2022-31167.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:24 +0000.