Skip to main content
Vulnerability Database/CVE-2024-45591

CVE-2024-45591: XWiki Platform Information Disclosure

CVE-2024-45591 is an information disclosure flaw in XWiki Platform that exposes page history data through the REST API regardless of access controls. This post covers the security implications, affected versions, and remediation strategies.

Published:

CVE-2024-45591 Overview

CVE-2024-45591 is an information disclosure vulnerability in XWiki Platform, a generic open-source wiki platform. The REST API endpoint for page history exposes modification metadata regardless of the configured access rights, including on wikis configured as fully private. An unauthenticated remote attacker who knows or guesses a page name can retrieve the modification timestamp, version number, author username, author display name, and version comment for every revision of that page. The vulnerability is tracked under CWE-359 (exposure of private personal information) and CWE-862 (missing authorization). It has been patched in XWiki 15.10.9 and 16.3.0RC1.

Critical Impact

Unauthenticated attackers can enumerate page revision history, author identities, and version comments on private XWiki instances, exposing user information and internal workflow context.

Affected Products

  • XWiki Platform versions prior to 15.10.9
  • XWiki Platform 16.x versions prior to 16.3.0RC1
  • All deployments exposing the XWiki REST API, including private wikis

Discovery Timeline

  • 2024-09-10 - CVE-2024-45591 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-45591

Vulnerability Analysis

The vulnerability resides in the XWiki REST API resources that serve page history data, specifically PageHistoryResourceImpl and PageTranslationHistoryResourceImpl. These resources returned the full revision history for any requested document without enforcing the document-level view rights defined in the wiki configuration. An attacker reaches the vulnerable endpoint by issuing an HTTP GET request to a path such as /xwiki/rest/wikis/xwiki/spaces/Main/pages/WebHome/history. If the response returns revision records, the instance is vulnerable.

Exposed fields for each revision include the modification time, version number, modifying user's username, their rendered display name, and the version comment field. On a fully private wiki, this breaks the expected confidentiality boundary by leaking author identities and workflow context to anonymous clients.

Root Cause

The REST history resources omitted authorization checks against the underlying document reference before returning revision metadata. The fix introduces a DocumentReference-based rights check and raises a WebApplicationException with an appropriate HTTP Response status when the caller lacks view permission on the target page.

Attack Vector

Exploitation requires only network access to the XWiki REST API and knowledge or guessing of a page name. No authentication, user interaction, or elevated privileges are required. Default pages such as Main.WebHome and XWiki.XWikiPreferences make enumeration trivial on standard deployments.

java
// Patch excerpt: PageHistoryResourceImpl.java (XWIKI-22052)
 import java.util.Date;
 import java.util.List;
 
+import javax.inject.Inject;
 import javax.inject.Named;
+import javax.ws.rs.WebApplicationException;
+import javax.ws.rs.core.Response;
 
 import org.xwiki.component.annotation.Component;
+import org.xwiki.model.reference.DocumentReference;
 import org.xwiki.query.Query;
 import org.xwiki.query.QueryException;
 import org.xwiki.rest.XWikiResource;

Source: XWiki Platform commit 9cbca98. The patch adds imports for DocumentReference, WebApplicationException, and Response, enabling the resource to resolve the target document and reject unauthorized callers before any history data is serialized.

Detection Methods for CVE-2024-45591

Indicators of Compromise

  • HTTP GET requests from unauthenticated or anonymous sources to URIs matching /xwiki/rest/wikis/*/spaces/*/pages/*/history or /history/*.
  • Successful (HTTP 200) history responses to clients that lack an authenticated session cookie or Authorization header.
  • Unusual volume of REST API requests enumerating page paths such as Main.WebHome, XWiki.XWikiPreferences, or sandbox pages.

Detection Strategies

  • Parse web server and reverse proxy logs for requests to the rest/.../history path pattern and correlate with the authentication state of the requester.
  • Alert on anonymous access to REST history endpoints on wikis configured as private, where authenticated access is expected for all content.
  • Baseline normal REST API usage per source IP and flag spikes consistent with scripted enumeration of page names.

Monitoring Recommendations

  • Enable verbose access logging on the servlet container or fronting proxy to capture full request URIs and user identity for the XWiki REST API.
  • Forward XWiki and proxy logs to a central analytics platform and retain them long enough to investigate retrospective enumeration against vulnerable versions.
  • Review user and author data referenced in public issue trackers or search engine caches to assess exposure prior to patching.

How to Mitigate CVE-2024-45591

Immediate Actions Required

  • Upgrade XWiki Platform to 15.10.9, 16.3.0RC1, or later as soon as possible.
  • Inventory internet-exposed XWiki instances and prioritize patching for any marked as private or hosting sensitive editorial workflows.
  • Validate the fix by issuing an anonymous request to /xwiki/rest/wikis/xwiki/spaces/Main/pages/WebHome/history and confirming an authorization error is returned.

Patch Information

The issue is tracked as XWIKI-22052 and documented in the GitHub Security Advisory GHSA-pvmm-55r5-g3mm. The upstream fixes are available in commits 26482ee and 9cbca98, which add proper rights handling to PageHistoryResourceImpl and PageTranslationHistoryResourceImpl.

Workarounds

  • Restrict access to the XWiki REST API at the reverse proxy or WAF layer, blocking anonymous requests to URIs containing /rest/wikis/*/spaces/*/pages/*/history.
  • Require authentication for all REST API traffic on private wiki deployments by enforcing a login check in the fronting web server.
  • Rotate or anonymize sensitive version comments on high-value pages until patching is complete, since historical data may already be cached by attackers.
bash
# Example nginx snippet to block anonymous access to the REST history endpoints
location ~* ^/xwiki/rest/wikis/.+/spaces/.+/pages/.+/history {
    if ($http_cookie !~* "JSESSIONID") {
        return 401;
    }
    proxy_pass http://xwiki_backend;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.