GHSA-2grh-gr37-2283

    Dashboard / Vulnerabilities / GHSA-2grh-gr37-2283

    GHSA-2grh-gr37-2283

    Published: 16 Dec 2023Last Modified: 10 Sept 2026

    Summary: Solr search discloses email addresses of users

    Details: ### Impact The Solr-based search in XWiki discloses the email addresses of users even when obfuscation of email addresses is enabled. To demonstrate the vulnerability, search for `objcontent:email*` using XWiki's regular search interface. ### Patches This has been fixed in XWiki 14.10.15, 15.5.2 and 15.7RC1 by not indexing email address properties when obfuscation is enabled. Further, changing the setting now triggers re-indexing of the affected wiki(s). ### Workarounds We're not aware of any workarounds. ### References * https://jira.xwiki.org/browse/XWIKI-20371 * https://github.com/xwiki/xwiki-platform/commit/3e5272f2ef0dff06a8f4db10afd1949b2f9e6eea ### Attribution This vulnerability was reported on Intigriti by [ynoof](https://twitter.com/ynoofAssiri) @Ynoof5.

    Affected packages

    Package

    Name: org.xwiki.platform:xwiki-platform-search-solr-api

    Purl: pkg:maven/org.xwiki.platform/xwiki-platform-search-solr-api

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -14.10.15

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-2grh-gr37-2283 | CVE-DB