🛡️ CVE-2024-46978 — xwiki

🟠 CVSS 8.0 — High ✅ No Known Exploit CWE-648 NVD
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

org.xwiki.platform:xwiki-platform-notifications-ui is missing checks for notification filter preferences editions

Impact

It's possible for any user knowing the ID of a notification filter preference of another user, to enable/disable it or even delete it. The impact is that the target user might start loosing notifications on some pages because of this.

This vulnerability is present in XWiki since 13.2-rc-1.

Patches

The vulnerability has been patched in XWiki 14.10.21, 15.5.5, 15.10.1, 16.0-rc-1. The patch consists in checking properly the rights of the user before performing any action on the filters.

Workarounds

It's possible to fix manually the vulnerability by editing the document XWiki.Notifications.Code.NotificationPreferenceService to apply the changes performed in this commit e8acc9d8e6af7dfbfe70716ded431642ae4a6dd4.

References

  • JIRA ticket: https://jira.xwiki.org/browse/XWIKI-20337
  • Commit: e8acc9d8e6af7dfbfe70716ded431642ae4a6dd4

For more information

If you have any questions or comments about this advisory:

Attribution

This vulnerability has been reported on Intigriti by @floerer

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity high, availability none.

Weakness class

CVE-2024-46978 is classified as CWE-648: Incorrect Use of Privileged APIs. The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.

Affected software

CVE-2024-46978 is recorded against 2 packages.

  • org.xwiki.platform:xwiki-platform-notifications-ui (from 15.6-rc-1 up to 15.10.1)
  • xwiki (from 15.6 up to 15.10.1)

Timeline and source

Published on 18 September 2024 and last revised on 18 November 2024. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Web)
github.com (Web)
github.com (Web)
github.com (Package)
jira.xwiki.org (Web)

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE CWE-648
Public Exploit ✅ No
Source NVD
Published 2024-09-18
Updated 2026-08-12
Modified 2024-11-18

Affected Packages

Software From version Fixed in
org.xwiki.platform:xwiki-platform-notifications-ui 15.6-rc-1 15.10.1
xwiki 15.6 15.10.1

Similar Threats

Site Security Check

Is xwiki part of your stack?

CVE-2024-46978 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2024