CVE-2023-45144
moderate-risk
Published 2023-10-16
com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and XWiki syntax injection. This allows remote code execution via the groovy macro and thus affects the confidentiality, integrity and availability of the whole XWiki installation. The issue has been fixed in Identity OAuth version 1.6. There are no known workarounds for this vulnerability and users are advised to upgrade.
Do I need to act?
~
4.1% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: f41901c5a01e00f9099dda289dfe79d17aa37ba7
10
CVSS 10.0/10
Critical
NETWORK
/ LOW complexity
Affected Products (1)
Oauth Identity
Affected Vendors
References (10)
Permissions Required
https://jira.xwiki.org/browse/XWIKI-20719
Permissions Required
https://jira.xwiki.org/browse/XWIKI-20719
45
/ 100
moderate-risk
Severity
33/34 · Critical
Exploitability
7/34 · Low
Exposure
5/34 · Minimal