Loading HuntDB...

GHSA-mvp5-qx9c-c3fv

GitHub Security Advisory

XWiki makes title of inaccessible pages available through the class property values REST API

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

### Impact
The title of every single page whose reference is known can be accessed through the REST API as long as an XClass with a page property is accessible, this is the default for an XWiki installation. This allows an attacker to get titles of pages whose reference is known, one title per request. This doesn't affect fully [private wikis](https://www.xwiki.org/xwiki/bin/view/Documentation/AdminGuide/Access%20Rights/#HPrivateWiki) as the REST endpoint checks access rights on the XClass definition. The impact on confidentiality depends on the strategy for page names. By default, page names match the title, so the impact should be low but if page names are intentionally obfuscated because the titles are sensitive, the impact could be high.

### Patches
This has been fixed in XWiki 16.4.7, 16.10.3 and 17.0.0 by adding access control checks before getting the title of any page.

### Workarounds
We're not aware of any workarounds.

Affected Packages

Maven org.xwiki.platform:xwiki-platform-rest-server
Affected versions: 10.9 (fixed in 16.4.7)
Maven org.xwiki.platform:xwiki-platform-rest-server
Affected versions: 16.5.0-rc-1 (fixed in 16.10.3)
Maven org.xwiki.platform:xwiki-platform-rest-server
Affected versions: 17.0.0-rc-1 (fixed in 17.0.0)

Related CVEs

Key Information

GHSA ID
GHSA-mvp5-qx9c-c3fv
Published
June 13, 2025 8:42 PM
Last Modified
June 13, 2025 8:42 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.xwiki.platform:xwiki-platform-rest-server
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.