CVE-2022-31167 - CVE House
Back to Database
Status published High CVE-2022-31167

XWiki Platform Security Parent POM vulnerable to overwriting of security rules of a page with a final page having the same reference

Vulnerability Description

XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.10.11, 13.10.1, and 13.4.6, a bug in the security cache stores rules associated to document Page1.Page2 and space Page1.Page2 in the same cache entry. That means that it's possible to overwrite the rights of a space or a document by creating the page of the space with the same name and checking the right of the new one first so that they end up in the security cache and are used for the other too. The problem has been patched in XWiki 12.10.11, 13.10.1, and 13.4.6. There are no known workarounds.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-31167

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

xwiki-platform
Vulnerable Versions:
>= 5.0, < 12.10.11, >= 13.0, < 13.4.6, >= 13.10, < 13.10.1

Timeline

Official Publish: September 7th, 2022
Last Modified: April 22nd, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Weaknesses (CWE)