CVE-2023-35151

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-35151
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-35151.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-35151
Aliases
Published
2023-06-23T16:33:01.388Z
Modified
2025-11-17T04:37:22.445154Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
XWiki Platform may show email addresses in clear in REST results
Details

XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activated. The issue has been patched in XWiki 14.4.8, 14.10.6, and 15.1. There is no known workaround.

Database specific
{
    "cwe_ids": [
        "CWE-359"
    ]
}
References

Affected packages

Git / github.com/xwiki/xwiki-commons

Affected ranges

Type
GIT
Repo
https://github.com/xwiki/xwiki-commons
Events

Git / github.com/xwiki/xwiki-platform

Affected ranges

Type
GIT
Repo
https://github.com/xwiki/xwiki-platform
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

xwiki-application-calendar-1.*

xwiki-application-calendar-1.0

xwiki-platform-7.*

xwiki-platform-7.3-milestone-2
xwiki-platform-7.4-milestone-1
xwiki-platform-7.4-milestone-2

xwiki-platform-8.*

xwiki-platform-8.0-milestone-1
xwiki-platform-8.0-milestone-2
xwiki-platform-8.1-milestone-1
xwiki-platform-8.1-milestone-2
xwiki-platform-8.2-milestone-1
xwiki-platform-8.2-milestone-2
xwiki-platform-8.3-milestone-1

xwiki-platform-9.*

xwiki-platform-9.9-rc-2

xwiki-plugin-tag-1.*

xwiki-plugin-tag-1.1

Database specific

vanir_signatures

[
    {
        "signature_version": "v1",
        "source": "https://github.com/xwiki/xwiki-platform/commit/824cd742ecf5439971247da11bfe7e0ad2b10ede",
        "signature_type": "Function",
        "id": "CVE-2023-35151-11fd10a1",
        "target": {
            "function": "fillObjectSummary",
            "file": "xwiki-platform-core/xwiki-platform-rest/xwiki-platform-rest-server/src/main/java/org/xwiki/rest/internal/ModelFactory.java"
        },
        "digest": {
            "length": 924.0,
            "function_hash": "92754167237679068064209207248576331644"
        },
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/xwiki/xwiki-platform/commit/824cd742ecf5439971247da11bfe7e0ad2b10ede",
        "signature_type": "Line",
        "id": "CVE-2023-35151-3e80ba4d",
        "target": {
            "file": "xwiki-platform-core/xwiki-platform-rest/xwiki-platform-rest-server/src/test/java/org/xwiki/rest/internal/ModelFactoryTest.java"
        },
        "digest": {
            "line_hashes": [
                "154029809629301434489511288868831448537",
                "314769993968674655163822613559611534117",
                "150298715257563687287988385226997562214",
                "63985336500446989922056013084022893380",
                "293536063665795540341459595765815687745",
                "286486521538722492380692922934271179346",
                "49985090948199703622444584966675260665",
                "225051430471274635660546379588760262909",
                "266531908019920957704818459161042223661",
                "40748181884081154045125936300194898311",
                "191502941434684271092340227816091072552",
                "106203087054297948390886316074255003665",
                "256208698412407527610425437683175636477",
                "337975312681884545996321057350031741235",
                "332599046450901250651525023904804604647",
                "165375474035735617266591166456231993317",
                "221900096748989176495132096832541107558",
                "31330244465445053637805730869287549902",
                "227067855327769585751253292960828430143",
                "44141578523587370614840969680293361671",
                "106024682309733793683937215819877465955",
                "94577426561350974189305460923371346707",
                "32963487151075881723140449996615938546",
                "168126205336991555045745409996651286402",
                "113033857194557069971835795798290001263",
                "337818406316451513379995345544094715281",
                "323754778321723177491671865475785703610",
                "134617165220199029682630995137583561232",
                "118736244615276292198095851806974986234",
                "86992130650277697588319001292194886933",
                "299612958958859022160249091112090435834",
                "140350727679835009498076282794344407729",
                "120626262857789274211841861477183458256",
                "3866737361911967442277294375632399008",
                "313288292650868762899438982224998275546",
                "183757285329110455443614591343807604240",
                "242458522049074367134588117580915383138",
                "227365220629612228042104812072640973917",
                "303563683185171035061068326784486002814",
                "164562066957424318742165171416708567254",
                "226889894981937152641873279055947522678",
                "323452639187455951782858054340246976644",
                "22009611940443522051136920921347394529",
                "95641415888229482685351933323523724977",
                "96219374142853268954385900314505072354"
            ],
            "threshold": 0.9
        },
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/xwiki/xwiki-platform/commit/824cd742ecf5439971247da11bfe7e0ad2b10ede",
        "signature_type": "Line",
        "id": "CVE-2023-35151-52b9bee7",
        "target": {
            "file": "xwiki-platform-core/xwiki-platform-rest/xwiki-platform-rest-server/src/main/java/org/xwiki/rest/internal/ModelFactory.java"
        },
        "digest": {
            "line_hashes": [
                "16640649287765843196554528938546037497",
                "212900781779656746574786280417023274013",
                "250225525172460908411827174158649204955",
                "330270241370842584908858483009244322870",
                "234578567184060738019238978681667128815",
                "172013442487161135381411538281779995261",
                "258264948007833375969981789860712047888",
                "113138269503157065504512330603192890003",
                "253798310934362867571013582197991817508",
                "250060351667552036504065272628876580037",
                "183240753696426368575196828151926437316",
                "150300425793348970428078659692200365376",
                "102384080335636646174705400499226990856",
                "275464874711005961135749785841864430350",
                "67172353303899664046670035201765753527",
                "160650225000265246663080132654397287520",
                "116085889568578497626490429164985197787",
                "145222167512795443626759848286562165066",
                "10444183329331488490557879343470073317",
                "70110972420392013371867156205426659287",
                "202732744952358090620165159441072298553",
                "56416982895225971556348052850360281192",
                "153083444619082393684169316698594348550",
                "32849856943306537952408258431149582756",
                "336184907595252304874339077635739213300",
                "268287327949040330402793763559153525294",
                "242543463397851456180372081562588023303",
                "14255999458195926363293637245792863387",
                "25039707802061292158049608758230602438",
                "235150301359025486633558145563816642870",
                "137073091676617257612035707609682094387",
                "292275135539594094642654630576192806671",
                "83222410103261934263020549538924265285",
                "240082715970259762533293750767289728010",
                "238398829624290994005129571070532814979",
                "102715412356406950219770955940244365114"
            ],
            "threshold": 0.9
        },
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/xwiki/xwiki-platform/commit/824cd742ecf5439971247da11bfe7e0ad2b10ede",
        "signature_type": "Function",
        "id": "CVE-2023-35151-5dd31fd8",
        "target": {
            "function": "getDefaultLocale",
            "file": "xwiki-platform-core/xwiki-platform-rest/xwiki-platform-rest-server/src/main/java/org/xwiki/rest/internal/ModelFactory.java"
        },
        "digest": {
            "length": 466.0,
            "function_hash": "64352183740611467500102991657998366914"
        },
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/xwiki/xwiki-platform/commit/824cd742ecf5439971247da11bfe7e0ad2b10ede",
        "signature_type": "Function",
        "id": "CVE-2023-35151-7b64ea4e",
        "target": {
            "function": "serializePropertyValue",
            "file": "xwiki-platform-core/xwiki-platform-rest/xwiki-platform-rest-server/src/main/java/org/xwiki/rest/internal/ModelFactory.java"
        },
        "digest": {
            "length": 569.0,
            "function_hash": "216443735803336568310600328023059309054"
        },
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/xwiki/xwiki-platform/commit/824cd742ecf5439971247da11bfe7e0ad2b10ede",
        "signature_type": "Function",
        "id": "CVE-2023-35151-851e1f1a",
        "target": {
            "function": "toRestHierarchy",
            "file": "xwiki-platform-core/xwiki-platform-rest/xwiki-platform-rest-server/src/main/java/org/xwiki/rest/internal/ModelFactory.java"
        },
        "digest": {
            "length": 1299.0,
            "function_hash": "36844270373376905169445282806781421621"
        },
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "source": "https://github.com/xwiki/xwiki-platform/commit/824cd742ecf5439971247da11bfe7e0ad2b10ede",
        "signature_type": "Function",
        "id": "CVE-2023-35151-982381c0",
        "target": {
            "function": "toRestObjectCheckWhichObjectValuesAreAvailableForAdmins",
            "file": "xwiki-platform-core/xwiki-platform-rest/xwiki-platform-rest-server/src/test/java/org/xwiki/rest/internal/ModelFactoryTest.java"
        },
        "digest": {
            "length": 460.0,
            "function_hash": "151636751455943976412323414729302468834"
        },
        "deprecated": false
    }
]