CVE Vulnerabilities

CVE-2024-52299

Generation of Predictable Numbers or Identifiers

Published: Nov 13, 2024 | Modified: Nov 18, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService can access any attachment stored in the wiki as the key that is passed to prevent this is computed incorrectly, calling skip on the digest stream doesnt update the digest. This is fixed in 2.5.6.

Weakness

The product uses a scheme that generates numbers or identifiers that are more predictable than required.

Affected Software

Name Vendor Start Version End Version
Pdf_viewer_macro Xwiki * 2.5.6 (excluding)

References