VDB
KO
MEDIUM 6.5

GHSA-4j38-rw27-97gx

org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages

Quick fix

GHSA-4j38-rw27-97gx — org.xwiki.contrib:discussions-server: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.0-rc-1</version> for org.xwiki.contrib:discussions-server

Details

### Impact It's possible to forge a request to delete a message.

### Patches The problem has been patched in version 2.0-rc-1 of Discussion Extension.

### Workarounds There's no easy workaround except upgrading.

### References https://jira.xwiki.org/browse/DISCUSSION-22

### For more information If you have any questions or comments about this advisory: * Open an issue in [Jira XWiki](https://jira.xwiki.org) * Email us at [security mailing-list](mailto:security@xwiki.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven / org.xwiki.contrib:discussions-server
Introduced in: 0 Fixed in: 2.0-rc-1
Fix # pom.xml: bump <version>2.0-rc-1</version> for org.xwiki.contrib:discussions-server

References