CVE-2022-29161
Last modified
CVE-2022-29161 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 certificates signed by default using SHA1 with RSA, which is not considered safe anymore for use in certificate signatures, due to the risk of collisions with SHA1. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 certificates signed by default using SHA1 with RSA, which is not considered safe anymore for use in certificate signatures, due to the risk of collisions with SHA1. The problem has been patched in XWiki version 13.10.6, 14.3.1 and 14.4-rc-1. Since then, the Crypto API will generate X509 certificates signed by default using SHA256 with RSA. Administrators are advised to upgrade their XWiki installation to one of the patched versions. If the upgrade is not possible, it is possible to patch the module xwiki-platform-crypto in a local installation by applying the change exposed in 26728f3 and re-compiling the module.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xwiki | Xwiki | < 13.10.6 |
| Xwiki | Xwiki | >= 14.0, < 14.3.1 |
References
- https://github.com/xwiki/xwiki-platform/commit/26728f3f23658288683667a5182a916c7ecefc52Patch, Third Party Advisory
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-h8v5-p258-pqf4Third Party Advisory
- https://jira.xwiki.org/browse/XWIKI-19676Vendor Advisory
- https://github.com/xwiki/xwiki-platform/commit/26728f3f23658288683667a5182a916c7ecefc52Patch, Third Party Advisory
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-h8v5-p258-pqf4Third Party Advisory
- https://jira.xwiki.org/browse/XWIKI-19676Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-29161?
How severe is CVE-2022-29161?
How do I fix CVE-2022-29161?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-29154An issue was discovered in rsync before 3.2.5 that allows ma…7.4
- CVE-2022-29155In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL …9.8
- CVE-2022-29156drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel b…7.8
- CVE-2022-29158Apache OFBiz up to version 18.12.05 is vulnerable to Regular…7.5
- CVE-2022-29159Nextcloud Deck is a Kanban-style project & personal manageme…4.3
- CVE-2022-29160Nextcloud Android is the Android client for Nextcloud, a sel…3.3
- CVE-2022-29162runc is a CLI tool for spawning and running containers on Li…7.8
- CVE-2022-29163Nextcloud Server is the file server software for Nextcloud, …4.3
- CVE-2022-29164Argo Workflows is an open source container-native workflow e…7.1
- CVE-2022-29165Argo CD is a declarative, GitOps continuous delivery tool fo…10
- CVE-2022-29166matrix-appservice-irc is a Node.js IRC bridge for Matrix. Th…8.8
- CVE-2022-29167Hawk is an HTTP authentication scheme providing mechanisms f…7.5
Are you affected by CVE-2022-29161?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
