XWiki 15.10.8

CPE Details

XWiki 15.10.8
15.10.8
2025-01-10
15h44 +00:00
2025-01-10
15h44 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:xwiki:xwiki:15.10.8:*:*:*:*:*:*:*

Informations

Vendor

xwiki

Product

xwiki

Version

15.10.8

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-45591 2024-09-10 15h56 +00:00 XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed information includes for each modification of the page the time of the modification, the version number, the author of the modification (both username and displayed name) and the version comment. This information is exposed regardless of the rights setup, and even when the wiki is configured to be fully private. On a private wiki, this can be tested by accessing /xwiki/rest/wikis/xwiki/spaces/Main/pages/WebHome/history, if this shows the history of the main page then the installation is vulnerable. This has been patched in XWiki 15.10.9 and XWiki 16.3.0RC1.
5.3
Medium