SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-32731

As a workaround, it is possible to manually modify the `resetpasswordinline.vm` to perform the changes made to mitigate the vulnerability.

MEDIUM 5.3EPSS 1.20%

Does this matter?

Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.

Description

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and including) versions 13.1RC1 and 13.1, the reset password form reveals the email address of users just by giving their username. The problem has been patched on XWiki 13.2RC1. As a workaround, it is possible to manually modify the `resetpasswordinline.vm` to perform the changes made to mitigate the vulnerability.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.20% probability · 66th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
xwiki/xwiki
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.