Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-1678

Security problem with the xar import

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Major
    • 2.2 M1
    • 1.1 RC1
    • {Unused} Packaging
    • None
    • Low

    Description

      When importing a XAR in a wiki, there is no verfication that the user who make the import
      has the same level of rights as the users that are listed in the pages inside the xar.

      So, if a user imports specially crafted xar, he can creates pages with groovy code that will
      be executed as more privileged users (for example farm's admins)

      Attachments

        Activity

          People

            jerome Jerome Velociter
            raffaello Raffaello Pelagalli
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: