Skip to content
Snippets Groups Projects
  1. Feb 24, 2015
    • Andreas Gohr's avatar
      check permissions in ACL plugin's RPC API component. #1056 · 9cbf80e6
      Andreas Gohr authored
      Security Fix
      
      Severity: Medium
      Type:     Remote Priviledge Escalation
      Remote:   yes
      
      Vulnerability Details:
      
      This fixes a security hole in the ACL plugins remote API component. The
      plugin failed to check for superuser permissions before executing ACL
      addition or deletion. This means everybody with permissions to call the
      XMLRPC API also had permissions to set up their own ACL rules and thus
      circumventing any existing rules.
      
      Risk Assessment:
      
      The XMLRPC API in DokuWiki is marked experimental and off by default. It
      also implements an additional safeguard by giving access to a configured
      circle of users and groups only. So only a minor number of DokuWiki
      installations will be affected at all.
      For affected installations the risk is high if users with access to the
      API are not to be trusted.
      Thus the overall severity of medium.
      
      Resolution:
      
      Installations applying this commit are safe. A hotfix is about to be
      released. Meanwhile users are advised to disable the XMLRPC API in the
      config manager.
      9cbf80e6
    • Andreas Gohr's avatar
      fixed the margin for the sidebar · 30c46635
      Andreas Gohr authored
      30c46635
    • Andreas Gohr's avatar
      15a61525
  2. Feb 17, 2015
  3. Feb 13, 2015
  4. Feb 12, 2015
  5. Feb 09, 2015
  6. Jan 28, 2015
  7. Jan 25, 2015
  8. Jan 15, 2015
  9. Jan 14, 2015
  10. Jan 12, 2015
  11. Jan 10, 2015
  12. Jan 08, 2015
  13. Jan 07, 2015
  14. Jan 05, 2015
  15. Dec 31, 2014
  16. Dec 30, 2014
  17. Dec 21, 2014
  18. Dec 20, 2014
  19. Dec 18, 2014
  20. Dec 17, 2014
  21. Dec 15, 2014
  22. Dec 14, 2014
  23. Dec 13, 2014
  24. Dec 12, 2014
  25. Dec 11, 2014
Loading