Creation of new database tables through login form on PostgreSQL
Package
Affected versions
< 13.10.8
>= 14.0.0, < 14.4.2
>= 14.5.0, < 14.6-rc-1
Patched versions
13.10.8
14.4.2
14.6-rc-1
Description
Published to the GitHub Advisory Database
Nov 21, 2022
Reviewed
Nov 21, 2022
Published by the National Vulnerability Database
Nov 23, 2022
Last updated
Jul 10, 2023
Impact
It's possible to make XWiki create many new schemas and fill them with tables just by using a crafted user identifier in the login form.
Patches
The problem has been patched in XWiki 13.10.8, 14.6RC1 and 14.4.2.
Workarounds
The only workarounds for this are:
References
https://jira.xwiki.org/browse/XWIKI-19886
For more information
If you have any questions or comments about this advisory:
References