Remote code execution from login screen through unescaped URL parameter in OAuth Identity XWiki App
CVE-2023-45144
What is CVE-2023-45144?
The identity-oauth-ui package allows OAuth-based login for XWiki applications. A vulnerability exists where the identityOAuth parameters within the GET request can be exploited through cross-site scripting (XSS) and XWiki syntax injection. Attackers may leverage this flaw to execute arbitrary code remotely via the groovy macro, leading to potential risks for the confidentiality, integrity, and availability of XWiki installations. Users are strongly advised to update to Identity OAuth version 1.6, as no workarounds are available for this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
identity-oauth >= 1.0, < 1.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
