Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3461 | XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki without any special right, view the document `Scheduler.WebHome` in a subwiki. Then, click on any operation (*e.g.,* Trigger) on any job. If the operation is successful, then the instance is vulnerable. This has been patched in XWiki 15.10.9 and 16.3.0. As a workaround, those who have subwikis where the Job Scheduler is enabled can edit the objects on `Scheduler.WebPreferences` to match the patch. |
Github GHSA |
GHSA-cwq6-mjmx-47p6 | XWiki's scheduler in subwiki allows scheduling operations for any main wiki user |
Wed, 30 Apr 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xwiki
Xwiki xwiki |
|
| CPEs | cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:* cpe:2.3:a:xwiki:xwiki:*:-:*:*:*:*:*:* cpe:2.3:a:xwiki:xwiki:1.2:-:*:*:*:*:*:* cpe:2.3:a:xwiki:xwiki:1.2:milestone2:*:*:*:*:*:* cpe:2.3:a:xwiki:xwiki:1.2:rc1:*:*:*:*:*:* cpe:2.3:a:xwiki:xwiki:1.2:rc2:*:*:*:*:*:* cpe:2.3:a:xwiki:xwiki:1.2:rc3:*:*:*:*:*:* |
|
| Vendors & Products |
Xwiki
Xwiki xwiki |
|
| Metrics |
cvssV3_1
|
Fri, 13 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki without any special right, view the document `Scheduler.WebHome` in a subwiki. Then, click on any operation (*e.g.,* Trigger) on any job. If the operation is successful, then the instance is vulnerable. This has been patched in XWiki 15.10.9 and 16.3.0. As a workaround, those who have subwikis where the Job Scheduler is enabled can edit the objects on `Scheduler.WebPreferences` to match the patch. | |
| Title | XWiki's scheduler in subwiki allows scheduling operations for any main wiki user | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-13T14:55:19.672Z
Reserved: 2024-12-11T15:46:36.421Z
Link: CVE-2024-55876
Updated: 2024-12-13T14:52:11.232Z
Status : Analyzed
Published: 2024-12-12T19:15:14.140
Modified: 2025-04-30T16:02:40.777
Link: CVE-2024-55876
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA