Exposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-livetable-ui,org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
Package
org.xwiki.platform:xwiki-platform-livetable-ui,org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
(Maven)
Affected versions
>= 3.2-m3
Patched versions
14.7-rc-1, 13.4.4, 13.10.9
Impact
Users can deduce the content of the password fields by repeated call to
LiveTableResults
andWikisLiveTableResultsMacros
.Patches
The issue is applied on versions 14.7-rc-1, 13.4.4, and 13.10.9.
Workarounds
The issue can be fixed by upgrading to versions 14.7-rc-1, 13.4.4, and 13.10.9 and higher, or in version >= 3.2M3 by applying the patch manually on
LiveTableResults
andWikisLiveTableResultsMacros
.References
For more information
If you have any questions or comments about this advisory: