CVE-2023-45144

com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and XWiki syntax injection. This allows remote code execution via the groovy macro and thus affects the confidentiality, integrity and availability of the whole XWiki installation. The issue has been fixed in Identity OAuth version 1.6. There are no known workarounds for this vulnerability and users are advised to upgrade.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xwiki:oauth_identity:*:*:*:*:*:*:*:*

History

20 Oct 2023, 20:00

Type Values Removed Values Added
First Time Xwiki
Xwiki oauth Identity
CPE cpe:2.3:a:xwiki:oauth_identity:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.6
CWE CWE-94
References (MISC) https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6#diff-2ab2e0716443d790d7d798320e4a45151661f4eca5440331f4a227b29c87c188 - (MISC) https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6#diff-2ab2e0716443d790d7d798320e4a45151661f4eca5440331f4a227b29c87c188 - Patch
References (MISC) https://github.com/xwikisas/identity-oauth/blob/master/ui/src/main/resources/IdentityOAuth/LoginUIExtension.vm#L58 - (MISC) https://github.com/xwikisas/identity-oauth/blob/master/ui/src/main/resources/IdentityOAuth/LoginUIExtension.vm#L58 - Broken Link
References (MISC) https://jira.xwiki.org/browse/XWIKI-20719 - (MISC) https://jira.xwiki.org/browse/XWIKI-20719 - Permissions Required
References (MISC) https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6 - (MISC) https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6 - Patch
References (MISC) https://github.com/xwikisas/identity-oauth/security/advisories/GHSA-h2rm-29ch-wfmh - (MISC) https://github.com/xwikisas/identity-oauth/security/advisories/GHSA-h2rm-29ch-wfmh - Vendor Advisory

17 Oct 2023, 12:38

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-16 21:15

Updated : 2023-10-20 20:00


NVD link : CVE-2023-45144

Mitre link : CVE-2023-45144


JSON object : View

Products Affected

xwiki

  • oauth_identity
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')