XWiki has no right protection on rollback action
CVE-2024-21648
Summary
The XWiki Platform exhibits a vulnerability related to access control, specifically within its rollback functionality. This flaw permits a user to revert to an earlier version of a page without adequate permission checks, potentially allowing access to rights that have been revoked. This issue has been addressed in the latest versions of the platform, which enforce proper role validation before permitting rollback actions. Users are advised to upgrade to versions 14.10.17, 15.5.3, or 15.8-rc-1 to mitigate associated security risks.
Affected Version(s)
xwiki-platform >= 1.0, < 14.10.17 < 1.0, 14.10.17
xwiki-platform >= 15.0-rc-1, < 15.5.3 < 15.0-rc-1, 15.5.3
xwiki-platform >= 15.6-rc-1, < 15.8-rc-1 < 15.6-rc-1, 15.8-rc-1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved