{"id":"GHSA-jp3m-p26h-mm7v","summary":"Apache JSPWiki CSRF due to crafted invocation on the Image plugin","details":"A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also be used to modify the email associated with the attacked account, and then a reset password request from the login page.","aliases":["CVE-2022-34158"],"modified":"2023-11-08T04:09:41.925588Z","published":"2022-08-05T00:00:31Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-08-11T15:53:13Z","nvd_published_at":"2022-08-04T07:15:00Z","cwe_ids":["CWE-352"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-34158"},{"type":"PACKAGE","url":"https://github.com/apache/jspwiki"},{"type":"WEB","url":"https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2022-34158"}],"affected":[{"package":{"name":"org.apache.jspwiki:jspwiki-main","ecosystem":"Maven","purl":"pkg:maven/org.apache.jspwiki/jspwiki-main"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11.3"}]}],"versions":["2.11.0","2.11.0.M1","2.11.0.M2","2.11.0.M3","2.11.0.M4","2.11.0.M5","2.11.0.M6","2.11.0.M7","2.11.0.M8","2.11.1","2.11.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-jp3m-p26h-mm7v/GHSA-jp3m-p26h-mm7v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}