{"id":"GHSA-pg4m-3gp6-hw4w","summary":"org.xwiki.platform:xwiki-platform-notifications-ui leaks data of notification filters of users","details":"### Impact\n\nIt's possible to get access to notification filters of any user by using a URL such as `\u003chostname\u003exwiki/bin/get/XWiki/Notifications/Code/NotificationFilterPreferenceLivetableResults?outputSyntax=plain&type=custom&user=\u003cusername\u003e`. This vulnerability impacts all versions of XWiki since 13.2-rc-1.\nThe filters do not provide much information (they mainly contain references which are public data in XWiki), though some info could be used in combination with other vulnerabilities.\n\n### Patches\n\nThe vulnerability has been patched in XWiki 14.10.21, 15.5.5, 15.10.1, 16.0RC1. \nThe patch consists in checking the rights of the user when sending the data.\n\n### Workarounds\n\nIt's possible to workaround the vulnerability by applying manually the patch: it's possible for an administrator to edit directly the document `XWiki.Notifications.Code.NotificationFilterPreferenceLivetableResults` to apply the same changes as in the patch. See c8c6545f9bde6f5aade994aa5b5903a67b5c2582.\n\n### References\n\n  * Jira ticket: https://jira.xwiki.org/browse/XWIKI-20336\n  * Commit: c8c6545f9bde6f5aade994aa5b5903a67b5c2582\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)\n* Email us at [Security Mailing List](mailto:security@xwiki.org)\n\n### Attribution\n\nThis vulnerability has been reported on Intigriti by [Mete](https://www.linkedin.com/in/metehan-kalkan-5a3201199).","aliases":["CVE-2024-46979"],"modified":"2024-09-18T19:23:22Z","published":"2024-09-18T14:26:20Z","database_specific":{"github_reviewed_at":"2024-09-18T14:26:20Z","nvd_published_at":"2024-09-18T18:15:07Z","cwe_ids":["CWE-200","CWE-359"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-pg4m-3gp6-hw4w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-46979"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/29e5edbb2b7068ada17290cea41e0aa8144e1294"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/a0352922a1a61e0e858a9be89d73f0665630a63a"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/c8c6545f9bde6f5aade994aa5b5903a67b5c2582"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/ed090d1aa228848d3860968c437b72db3b09119f"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"},{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-20336"}],"affected":[{"package":{"name":"org.xwiki.platform:xwiki-platform-notifications-ui","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-notifications-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13.2-rc-1"},{"fixed":"14.10.21"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-pg4m-3gp6-hw4w/GHSA-pg4m-3gp6-hw4w.json"}},{"package":{"name":"org.xwiki.platform:xwiki-platform-notifications-ui","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-notifications-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15.0-rc-1"},{"fixed":"15.5.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-pg4m-3gp6-hw4w/GHSA-pg4m-3gp6-hw4w.json"}},{"package":{"name":"org.xwiki.platform:xwiki-platform-notifications-ui","ecosystem":"Maven","purl":"pkg:maven/org.xwiki.platform/xwiki-platform-notifications-ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15.6-rc-1"},{"fixed":"15.10.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-pg4m-3gp6-hw4w/GHSA-pg4m-3gp6-hw4w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}