XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit right can copy the content of a page it does not have access to by using it as template of a new page. This issue has been patched in XWiki 13.2CR1 and 12.10.6. Users are advised to update. There are no known workarounds for this issue.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-862"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23617.json"
}{
"source": [
"CPE_RANGE",
"CPE_STRING"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "12.10.5"
},
{
"last_affected": "13.0"
},
{
"last_affected": "13.1-NA"
}
],
"cpe": [
"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*",
"cpe:2.3:a:xwiki:xwiki:13.0:*:*:*:*:*:*:*",
"cpe:2.3:a:xwiki:xwiki:13.1:-:*:*:*:*:*:*"
]
}{
"source": [
"CPE_RANGE",
"CPE_STRING",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "12.10.5"
},
{
"last_affected": "13.0"
},
{
"last_affected": "13.1-NA"
}
],
"cpe": [
"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*",
"cpe:2.3:a:xwiki:xwiki:13.0:*:*:*:*:*:*:*",
"cpe:2.3:a:xwiki:xwiki:13.1:-:*:*:*:*:*:*"
]
}