Description

XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Starting in version 2.17.1 and prior to version 2.18.2, anyone with VIEW access to a user profile can create a token for that user. If that XWiki instance is configured to allow token authentication, it allows authentication with any user (since users are very commonly viewable, at least to other registered users). Version 2.18.2 contains a patch. As a workaround, disable token access.

INFO

Published Date :

2025-10-06T14:48:43.609Z

Last Modified :

2025-10-23T13:16:52.688Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-49594 vulnerability.

Vendors Products
Xwiki
  • Xwiki

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability