Skip to content
Snippets Groups Projects
  1. Dec 29, 2015
  2. Nov 17, 2015
  3. Nov 08, 2015
  4. Aug 28, 2015
  5. Aug 01, 2015
  6. Jul 26, 2015
  7. Jul 25, 2015
  8. Jul 15, 2015
  9. Jul 12, 2015
  10. Jun 30, 2015
  11. May 14, 2015
  12. May 08, 2015
  13. May 07, 2015
  14. Apr 16, 2015
  15. Feb 24, 2015
    • Andreas Gohr's avatar
      check permissions in ACL plugin's RPC API component. #1056 · 9cbf80e6
      Andreas Gohr authored
      Security Fix
      
      Severity: Medium
      Type:     Remote Priviledge Escalation
      Remote:   yes
      
      Vulnerability Details:
      
      This fixes a security hole in the ACL plugins remote API component. The
      plugin failed to check for superuser permissions before executing ACL
      addition or deletion. This means everybody with permissions to call the
      XMLRPC API also had permissions to set up their own ACL rules and thus
      circumventing any existing rules.
      
      Risk Assessment:
      
      The XMLRPC API in DokuWiki is marked experimental and off by default. It
      also implements an additional safeguard by giving access to a configured
      circle of users and groups only. So only a minor number of DokuWiki
      installations will be affected at all.
      For affected installations the risk is high if users with access to the
      API are not to be trusted.
      Thus the overall severity of medium.
      
      Resolution:
      
      Installations applying this commit are safe. A hotfix is about to be
      released. Meanwhile users are advised to disable the XMLRPC API in the
      config manager.
      9cbf80e6
  16. Jan 14, 2015
  17. Dec 30, 2014
  18. Dec 13, 2014
  19. Oct 15, 2014
  20. Oct 01, 2014
  21. Sep 29, 2014
  22. Sep 16, 2014
  23. Aug 02, 2014
  24. Jul 12, 2014
  25. Jul 10, 2014
  26. May 30, 2014
  27. May 15, 2014
  28. Apr 26, 2014
  29. Apr 22, 2014
  30. Mar 13, 2014
  31. Mar 12, 2014
  32. Mar 11, 2014
  33. Mar 08, 2014
  34. Mar 06, 2014
  35. Mar 05, 2014
  36. Jan 24, 2014
  37. Dec 30, 2013
  38. Dec 19, 2013
Loading