{"id":"GHSA-m7gv-v8xx-v47w","summary":"XWiki OIDC Authenticator vulnerable to bypassing OpenID login by providing a custom provider","details":"### Impact\n\nEven if a wiki has an OpenID provider configured through its xwiki.properties, it is possible to provide a third party provider by providing its details through request parameters. One can then bypass the XWiki authentication altogether by specifying its own provider through the oidc.endpoint.* request parameters (or by using an XWiki-based OpenID provider with oidc.xwikiprovider.\n\nWith the same approach, one could also provide a specific group mapping through oidc.groups.mapping that would make his user automatically part of the XWikiAdminGroup\n\n### Patches\n\nPatched in version 1.29.1.\n\n### Workarounds\n\nThere is no workaround, an upgrade of the authenticator is required.\n\n### References\n\nhttps://jira.xwiki.org/browse/OIDC-118\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Open an issue in Jira XWiki\n* Email us at our security mailing list\n\n","aliases":["CVE-2022-39387"],"modified":"2023-11-08T04:10:20.653987Z","published":"2022-11-04T18:58:46Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-11-04T18:58:46Z","nvd_published_at":"2022-11-04T19:15:00Z","cwe_ids":["CWE-287"]},"references":[{"type":"WEB","url":"https://github.com/xwiki-contrib/oidc/security/advisories/GHSA-m7gv-v8xx-v47w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-39387"},{"type":"WEB","url":"https://github.com/xwiki-contrib/oidc/commit/0247af1417925b9734ab106ad7cd934ee870ac89"},{"type":"PACKAGE","url":"https://github.com/xwiki-contrib/oidc"},{"type":"WEB","url":"https://jira.xwiki.org/browse/OIDC-118"}],"affected":[{"package":{"name":"org.xwiki.contrib.oidc:oidc-authenticator","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.contrib.oidc/oidc-authenticator"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.29.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-m7gv-v8xx-v47w/GHSA-m7gv-v8xx-v47w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}