Loading HuntDB...

GHSA-vvp7-r422-rx83

GitHub Security Advisory

Unauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm

✓ GitHub Reviewed LOW Has CVE

Advisory Details

### Impact

It's possible to list some users who are normally not viewable from subwiki by requesting users on a subwiki which allows only global users with `uorgsuggest.vm`. This issue only concerns hidden users from main wiki.
Note that the disclosed information are the username and the first and last name of users, no other information is leaked.

### Patches

The problem has been patched on XWiki 13.10.8, 14.4.3 and 14.7RC1.

### Workarounds

It's possible to workaround this vulnerability by patching directly `uorgsuggest.vm ` to apply the same changes as in https://github.com/xwiki/xwiki-platform/pull/1883.

### References

* JIRA ticket: https://jira.xwiki.org/browse/XWIKI-20007
* this vulnerability is actually a remaining of https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-97jg-43c9-q6pf which wasn't entirely fixed back then

### For more information

If you have any questions or comments about this advisory:
* Open an issue in [Jira](https://jira.xwiki.org)
* Email us at [security ML](mailto:[email protected])

Affected Packages

Maven org.xwiki.platform:xwiki-platform-web-templates
Affected versions: 13.9-rc-1 (fixed in 13.10.8)
Maven org.xwiki.platform:xwiki-platform-web-templates
Affected versions: 14.0-rc-1 (fixed in 14.4.3)
Maven org.xwiki.platform:xwiki-platform-web-templates
Affected versions: 14.5 (fixed in 14.7-rc-1)

Related CVEs

Key Information

GHSA ID
GHSA-vvp7-r422-rx83
Published
April 12, 2023 8:40 PM
Last Modified
April 16, 2023 7:18 AM
CVSS Score
2.5 /10
Primary Ecosystem
Maven
Primary Package
org.xwiki.platform:xwiki-platform-web-templates
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 23, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.