CVE-2024-46979
Last modified
CVE-2024-46979 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification filters of any user by using a URL such as `<hostname>xwiki/bin/get/XWiki/Notifications/Code/NotificationFilterPreferenceLivetableResults?outputSyntax=plain&type=custom&user=<username>`. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification filters of any user by using a URL such as `<hostname>xwiki/bin/get/XWiki/Notifications/Code/NotificationFilterPreferenceLivetableResults?outputSyntax=plain&type=custom&user=<username>`. This vulnerability impacts all versions of XWiki since 13.2-rc-1. The filters do not provide much information (they mainly contain references which are public data in XWiki), though some info could be used in combination with other vulnerabilities. This vulnerability has been patched in XWiki 14.10.21, 15.5.5, 15.10.1, 16.0RC1. The patch consists in checking the rights of the user when sending the data. Users are advised to upgrade. It's possible to workaround the vulnerability by applying manually the patch: it's possible for an administrator to edit directly the document `XWiki.Notifications.Code.NotificationFilterPreferenceLivetableResults` to apply the same changes as in the patch. See commit c8c6545f9bde6f5aade994aa5b5903a67b5c2582.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xwiki | Xwiki | >= 13.2, < 14.10.21 |
| Xwiki | Xwiki | >= 15.0, < 15.5.5 |
| Xwiki | Xwiki | >= 15.6, < 15.10.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-46979?
How severe is CVE-2024-46979?
How do I fix CVE-2024-46979?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-46973Software installed and run as a non-privileged user may cond…7.8
- CVE-2024-46974Software installed and run as a non-privileged user may cond…7.8
- CVE-2024-46975Kernel software installed and running inside a Guest VM may …7.9
- CVE-2024-46976Backstage is an open framework for building developer portal…5.4
- CVE-2024-46977OpenC3 COSMOS provides the functionality needed to send comm…6.5
- CVE-2024-46978XWiki Platform is a generic wiki platform offering runtime s…6.5
- CVE-2024-4698The Testimonial Carousel For Elementor plugin for WordPress …6.4
- CVE-2024-46980Tuleap is a tool for end to end traceability of application …4.8
- CVE-2024-46981Redis is an open source, in-memory database that persists on…9.8
- CVE-2024-46982Next.js is a React framework for building full-stack web app…7.5
- CVE-2024-46983sofa-hessian is an internal improved version of Hessian3/4 p…9.8
- CVE-2024-46984The reference validator is a tool to perform advanced valida…9.8
Are you affected by CVE-2024-46979?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
