Skip to content
Snippets Groups Projects
  1. Jun 30, 2015
  2. May 14, 2015
  3. Apr 16, 2015
  4. Feb 24, 2015
    • Andreas Gohr's avatar
      check permissions in ACL plugin's RPC API component. #1056 · 9cbf80e6
      Andreas Gohr authored
      Security Fix
      
      Severity: Medium
      Type:     Remote Priviledge Escalation
      Remote:   yes
      
      Vulnerability Details:
      
      This fixes a security hole in the ACL plugins remote API component. The
      plugin failed to check for superuser permissions before executing ACL
      addition or deletion. This means everybody with permissions to call the
      XMLRPC API also had permissions to set up their own ACL rules and thus
      circumventing any existing rules.
      
      Risk Assessment:
      
      The XMLRPC API in DokuWiki is marked experimental and off by default. It
      also implements an additional safeguard by giving access to a configured
      circle of users and groups only. So only a minor number of DokuWiki
      installations will be affected at all.
      For affected installations the risk is high if users with access to the
      API are not to be trusted.
      Thus the overall severity of medium.
      
      Resolution:
      
      Installations applying this commit are safe. A hotfix is about to be
      released. Meanwhile users are advised to disable the XMLRPC API in the
      config manager.
      9cbf80e6
  5. Jan 14, 2015
  6. Dec 30, 2014
  7. Dec 13, 2014
  8. Oct 15, 2014
  9. Oct 01, 2014
  10. Sep 29, 2014
  11. Sep 16, 2014
  12. Aug 02, 2014
  13. Jul 12, 2014
  14. Jul 10, 2014
  15. May 30, 2014
  16. May 15, 2014
  17. Apr 26, 2014
  18. Apr 22, 2014
  19. Mar 13, 2014
  20. Mar 12, 2014
  21. Mar 11, 2014
  22. Mar 08, 2014
  23. Mar 06, 2014
  24. Mar 05, 2014
  25. Jan 24, 2014
  26. Dec 30, 2013
  27. Dec 19, 2013
  28. Dec 06, 2013
  29. Dec 03, 2013
  30. Nov 25, 2013
  31. Nov 24, 2013
  32. Nov 13, 2013
  33. Oct 28, 2013
  34. Oct 25, 2013
Loading