{"id":"CVE-2025-49594","summary":"XWiki OIDC Authenticator vulnerable to creation of token for any user with just `view` right","details":"XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Starting in version 2.17.1 and prior to version 2.18.2, anyone with VIEW access to a user profile can create a token for that user. If that XWiki instance is configured to allow token authentication, it allows authentication with any user (since users are very commonly viewable, at least to other registered users). Version 2.18.2 contains a patch. As a workaround, disable token access.","aliases":["GHSA-f2hf-pfrj-vrm7"],"modified":"2026-08-12T15:13:55.418246Z","published":"2025-10-06T14:48:43.609Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-285"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49594.json"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/OIDC-240"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/cve-2025-49594-detect-xwiki-vulnerability"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/cve-2025-49594-mitigate-xwiki-vulnerability"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49594.json"},{"type":"ADVISORY","url":"https://github.com/xwiki-contrib/oidc/security/advisories/GHSA-f2hf-pfrj-vrm7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49594"},{"type":"FIX","url":"https://github.com/xwiki-contrib/oidc/commit/d90d717172283aaa96bb5bb44e357f910ae64adb"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xwiki-contrib/oidc","events":[{"introduced":"46f78862c24fa2df959293bdb58fd148fc0cfda1"},{"fixed":"d90d717172283aaa96bb5bb44e357f910ae64adb"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"2.17.1"},{"fixed":"2.18.2"}]}}],"versions":["oidc-2.18.1","oidc-2.18.0","oidc-2.17.4","oidc-2.17.3","oidc-2.17.2","oidc-2.17.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49594.json","vanir_signatures_modified":"2026-08-12T15:13:55Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"129946113780309351542741137391691015184","length":181},"id":"CVE-2025-49594-705335ce","signature_type":"Function","signature_version":"v1","source":"https://github.com/xwiki-contrib/oidc/commit/d90d717172283aaa96bb5bb44e357f910ae64adb","target":{"function":"gotToClientLogin","file":"oidc-test/oidc-test-tests/src/test/it/org/xwiki/oidc/test/OIDCTest.java"}},{"target":{"function":"authenticate","file":"oidc-test/oidc-test-tests/src/test/it/org/xwiki/oidc/test/OIDCTest.java"},"deprecated":false,"digest":{"function_hash":"188980292455528951297510936192278477097","length":1617},"id":"CVE-2025-49594-8381e2c4","signature_type":"Function","signature_version":"v1","source":"https://github.com/xwiki-contrib/oidc/commit/d90d717172283aaa96bb5bb44e357f910ae64adb"},{"source":"https://github.com/xwiki-contrib/oidc/commit/d90d717172283aaa96bb5bb44e357f910ae64adb","target":{"file":"oidc-test/oidc-test-pageobjects/src/main/java/org/xwiki/contrib/oidc/test/po/OIDCApplicationsUserProfilePage.java"},"deprecated":false,"digest":{"line_hashes":["241991066023059200211056234269667645337","332590395925087921627746333500413674385","335638851061567261054746334414547722186"],"threshold":0.9},"id":"CVE-2025-49594-c358f74e","signature_type":"Line","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/xwiki-contrib/oidc/commit/d90d717172283aaa96bb5bb44e357f910ae64adb","target":{"file":"oidc-test/oidc-test-tests/src/test/it/org/xwiki/oidc/test/OIDCTest.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["229528794327524446060903896261905976414","139165536846402449262115918778148651038","88962898386376036737307147338619854897","79147450128081559006842428430061934995","197465954177930890294324174118029910444","142119685924524377739373484297605504347","159369312681646380229415035545432665202","37944239998772979222556235683157754608","5368919076969964730266111657222800545","184837152916194442254233953502163593767","237858823074161969043858417201417490760","325818077261712919860286418637098457542","297279304858854793038754434725386691715","177997140429792642100668255333929835728","97630744059405324932080733883942495990","326463469950490921736858190506923192771","28342911674825607708937696878419416935","49737827580179370130473111916934261804","331693214186501240357396672343118176364","292445535845504274564627410826323931220","285963409915173775371271592243078756807","20211591574812166509456297708813300594","275437397108146179701200569362692182583","38943569287977992884306614471398302128","115784782417022270488302713759489354659","332436537174201283614325213576527553927","162514276196985102505429502555326481921","127337490145415721666026933085541089928","111826637977999686880350869331607179235","273823186347110169693755587206591458443","177642719496994047534821010543039249385"]},"id":"CVE-2025-49594-e565227a"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}