GHSA-2grh-gr37-2283
Solr search discloses email addresses of users
Quick fix
GHSA-2grh-gr37-2283 — org.xwiki.platform:xwiki-platform-search-solr-api: upgrade to the fixed version with the command below.
# pom.xml: bump <version>14.10.15</version> for org.xwiki.platform:xwiki-platform-search-solr-apiDetails
### Impact The Solr-based search in XWiki discloses the email addresses of users even when obfuscation of email addresses is enabled. To demonstrate the vulnerability, search for `objcontent:email*` using XWiki's regular search interface.
### Patches This has been fixed in XWiki 14.10.15, 15.5.2 and 15.7RC1 by not indexing email address properties when obfuscation is enabled. Further, changing the setting now triggers re-indexing of the affected wiki(s).
### Workarounds We're not aware of any workarounds.
### References * https://jira.xwiki.org/browse/XWIKI-20371 * https://github.com/xwiki/xwiki-platform/commit/3e5272f2ef0dff06a8f4db10afd1949b2f9e6eea
### Attribution This vulnerability was reported on Intigriti by [ynoof](https://twitter.com/ynoofAssiri) @Ynoof5.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 14.10.15# pom.xml: bump <version>14.10.15</version> for org.xwiki.platform:xwiki-platform-search-solr-api15.0-rc-1Fixed in: 15.5.2# pom.xml: bump <version>15.5.2</version> for org.xwiki.platform:xwiki-platform-search-solr-api15.6-rc-1Fixed in: 15.7-rc-1# pom.xml: bump <version>15.7-rc-1</version> for org.xwiki.platform:xwiki-platform-search-solr-apiReferences
- https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-2grh-gr37-2283[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-50720[ADVISORY]
- https://github.com/xwiki/xwiki-platform/commit/3e5272f2ef0dff06a8f4db10afd1949b2f9e6eea[WEB]
- https://github.com/xwiki/xwiki-platform[PACKAGE]
- https://jira.xwiki.org/browse/XWIKI-20371[WEB]