CVE-2024-31464

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Apr 10, 2024
CWE ID 200

Summary

CVE-2024-31464 is a vulnerability affecting XWiki Platform, a generic wiki solution. In versions prior to 14.10.19, 15.5.4, and 15.9-rc1, the deletion of an object storing a password allows access to the password hash using the diff feature. This is particularly concerning for user profiles, where an attacker with editing rights (typically limited to Admins) can exploit this vulnerability. The risk extends to extensions using xobjects for password storage, depending on their access rights. The extent of exploitation cannot be definitively determined, but it requires Admin privileges. To mitigate the risk, administrators should ensure proper protection of user pages, restricting editing rights to Admins and profile owners. XWiki users are advised to change passwords on potentially affected pages and consider upgrading to a secure version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share