Impact
POST /wikis/{wikiName} executes a XAR import without performing any authentication or authorization checks, allowing an unauthenticated attacker to create or update documents in the target wiki
Patches
This vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, 18.0.1 and 18.1.0-rc-1.
Workarounds
We're not aware of any workarounds except for adding a rule in an HTTP proxy to prevent access POST request in the /wikis/{wikiName}[/] endpoint.
References
For more information
If you have any questions or comments about this advisory:
Attribution
Reported by Sho Odagiri (GMO Cybersecurity by Ierae, Inc.).
Impact
POST /wikis/{wikiName}executes a XAR import without performing any authentication or authorization checks, allowing an unauthenticated attacker to create or update documents in the target wikiPatches
This vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, 18.0.1 and 18.1.0-rc-1.
Workarounds
We're not aware of any workarounds except for adding a rule in an HTTP proxy to prevent access POST request in the
/wikis/{wikiName}[/]endpoint.References
For more information
If you have any questions or comments about this advisory:
Attribution
Reported by Sho Odagiri (GMO Cybersecurity by Ierae, Inc.).