xwiki contains Exposed Dangerous Method or Function
Package
Affected versions
>= 14.3-rc-1, < 14.4.6
>= 14.5, < 14.9-rc-1
Patched versions
14.4.6
14.9-rc-1
Description
Published by the National Vulnerability Database
Mar 2, 2023
Published to the GitHub Advisory Database
Mar 3, 2023
Reviewed
Mar 3, 2023
Impact
org.xwiki.store.script.TemporaryAttachmentsScriptService#uploadTemporaryAttachmentis returning an instance ofcom.xpn.xwiki.doc.XWikiAttachment. This class is not supported to be exposed to users without theprogramingright.com.xpn.xwiki.api.Attachmentshould be used instead and takes case of checking the user's rights before performing dangerous operations.Patches
This has been patched in the version 14.9-rc-1 and 14.4.6.
Workarounds
There's no workaround for this issue.
References
https://jira.xwiki.org/browse/XWIKI-20180
For more information
If you have any questions or comments about this advisory:
References