CVE-2023-45144

com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and XWiki syntax injection. This allows remote code execution via the groovy macro and thus affects the confidentiality, integrity and availability of the whole XWiki installation. The issue has been fixed in Identity OAuth version 1.6. There are no known workarounds for this vulnerability and users are advised to upgrade.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xwiki:oauth_identity:*:*:*:*:*:*:*:*

History

20 Oct 2023, 20:00

Type Values Removed Values Added
References (MISC) https://github.com/xwikisas/identity-oauth/security/advisories/GHSA-h2rm-29ch-wfmh - (MISC) https://github.com/xwikisas/identity-oauth/security/advisories/GHSA-h2rm-29ch-wfmh - Vendor Advisory
References (MISC) https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6#diff-2ab2e0716443d790d7d798320e4a45151661f4eca5440331f4a227b29c87c188 - (MISC) https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6#diff-2ab2e0716443d790d7d798320e4a45151661f4eca5440331f4a227b29c87c188 - Patch
References (MISC) https://jira.xwiki.org/browse/XWIKI-20719 - (MISC) https://jira.xwiki.org/browse/XWIKI-20719 - Permissions Required
References (MISC) https://github.com/xwikisas/identity-oauth/blob/master/ui/src/main/resources/IdentityOAuth/LoginUIExtension.vm#L58 - (MISC) https://github.com/xwikisas/identity-oauth/blob/master/ui/src/main/resources/IdentityOAuth/LoginUIExtension.vm#L58 - Broken Link
References (MISC) https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6 - (MISC) https://github.com/xwikisas/identity-oauth/commit/d805d3154b17c6bf455ddf5deb0a3461a3833bc6 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.6
CWE CWE-94
CPE cpe:2.3:a:xwiki:oauth_identity:*:*:*:*:*:*:*:*
First Time Xwiki oauth Identity
Xwiki

16 Oct 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-16 21:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-45144

Mitre link : CVE-2023-45144

CVE.ORG link : CVE-2023-45144


JSON object : View

Products Affected

xwiki

  • oauth_identity
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')