Obfuscated email addresses should not be sorted
Moderate severity
GitHub Reviewed
Published
Jul 27, 2023
in
xwiki/xwiki-platform
•
Updated Mar 18, 2024
Package
Affected versions
>= 3.5-milestone-1, < 14.10.9
>= 15.0, < 15.3-rc-1
Patched versions
14.10.9
15.3-rc-1
Description
Published to the GitHub Advisory Database
Jul 27, 2023
Reviewed
Jul 27, 2023
Published by the National Vulnerability Database
Nov 7, 2023
Last updated
Mar 18, 2024
Impact
The mail obfuscation configuration was not fully taken into account and is was still possible by obfuscated emails.
See https://jira.xwiki.org/browse/XWIKI-20601 for the reproduction steps.
Patches
This has been patched in XWiki 14.10.9, and XWiki 15.3-rc-1.
Workarounds
The workaround is to modify the page XWiki.LiveTableResultsMacros following this patch.
References
For more information
If you have any questions or comments about this advisory:
References