CVE-2023-37465
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
Summary
### Impact It's possible to forge a request to delete a message. ### Patches The problem has been patched in version 2.0-rc-1 of Discussion Extension. ### Workarounds There's no easy workaround except upgrading. ### References https://jira.xwiki.org/browse/DISCUSSION-22 ### For more information If you have any questions or comments about this advisory: * Open an issue in [Jira XWiki](https://jira.xwiki.org) * Email us at [security mailing-list](mailto:[email protected])
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| Maven | org.xwiki.contrib:discussions-server | — | 2.0-rc-1 |
Remediation: Upgrade to 2.0-rc-1 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.