Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.xwiki.platform/xwiki-platform-web-templates
  4. ›
  5. CVE-2023-29203

CVE-2023-29203: Unauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm

April 12, 2023

Impact

It’s possible to list some users who are normally not viewable from subwiki by requesting users on a subwiki which allows only global users with uorgsuggest.vm. This issue only concerns hidden users from main wiki. Note that the disclosed information are the username and the first and last name of users, no other information is leaked.

Patches

The problem has been patched on XWiki 13.10.8, 14.4.3 and 14.7RC1.

Workarounds

It’s possible to workaround this vulnerability by patching directly uorgsuggest.vm to apply the same changes as in https://github.com/xwiki/xwiki-platform/pull/1883.

References

  • JIRA ticket: https://jira.xwiki.org/browse/XWIKI-20007
  • this vulnerability is actually a remaining of https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-97jg-43c9-q6pf which wasn’t entirely fixed back then

For more information

If you have any questions or comments about this advisory:

  • Open an issue in Jira
  • Email us at security ML

References

  • github.com/advisories/GHSA-vvp7-r422-rx83
  • github.com/xwiki/xwiki-platform/pull/1883
  • github.com/xwiki/xwiki-platform/security/advisories/GHSA-97jg-43c9-q6pf
  • github.com/xwiki/xwiki-platform/security/advisories/GHSA-vvp7-r422-rx83
  • jira.xwiki.org/browse/XWIKI-20007

Code Behaviors & Features

Detect and mitigate CVE-2023-29203 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 13.9-rc-1 before 13.10.8, all versions starting from 14.0-rc-1 before 14.4.3, all versions starting from 14.5 before 14.7-rc-1

Fixed versions

  • 13.10.8
  • 14.4.3
  • 14.7-rc-1

Solution

Upgrade to versions 13.10.8, 14.4.3, 14.7-rc-1 or above. *Note*: 14.7-rc-1 may be an unstable version. Use caution.

Impact 5.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Source file

maven/org.xwiki.platform/xwiki-platform-web-templates/CVE-2023-29203.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:44 +0000.