CVE-2022-41929

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/11/2022
Last modified:
30/11/2022

Description

org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorrectly authorized user with only Script rights to enable or disable a user. This operation is meant to only be available for users with admin rights. This problem has been patched in XWiki 13.10.7, 14.4.2 and 14.5RC1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* 11.7 (excluding) 13.10.7 (excluding)
cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:undefined 14.0.0 (excluding) 14.4.2 (excluding)
cpe:2.3:a:xwiki:xwiki:11.7:rc1:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:14.4.3:*:*:*:*:*:*:*
cpe:2.3:a:xwiki:xwiki:14.4.4:*:*:*:*:*:*:*