Vulnerability record · CVE-2023-48241 · published 20 November 2023
CVE-2023-48241: XWiki Solr search API authorization bypass exposes all wiki documents
Xwiki · Xwiki
XWiki Platform's Solr-based search suggestion provider, which also serves as a generic JavaScript API for search results, exposes the content of all documents across all wikis to anyone with access to it, and it is public by default. The normal right check can be bypassed by explicitly requesting Solr fields that omit the data used for the authorization check, so the flaw is an improper authorization issue rather than a memory or injection bug.
Description
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based search suggestion provider that also duplicates as generic JavaScript API for search results in XWiki exposes the content of all documents of all wikis to anybody who has access to it, by default it is public. This exposes all information stored in the wiki (but not some protected information like password hashes). While there is a right check normally, the right check can be circumvented by explicitly requesting fields from Solr that don't include the data for the right check. This has been fixed in XWiki 15.6RC1, 15.5.1 and 14.10.15 by not listing documents whose rights cannot be checked. No known workarounds are available.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 with no authentication or interaction required and a very high EPSS score, though no KEV listing or documented exploitation yet.
What it is
XWiki Platform's Solr-based search suggestion provider, which also serves as a generic JavaScript API for search results, exposes the content of all documents across all wikis to anyone with access to it, and it is public by default. The normal right check can be bypassed by explicitly requesting Solr fields that omit the data used for the authorization check, so the flaw is an improper authorization issue rather than a memory or injection bug.
Impact
An unauthenticated attacker can read the content of every document in every wiki, including content that should be restricted by rights. Protected material such as password hashes is not exposed, but the bulk of stored wiki information is.
Attack surface
Reachable over the network through the Solr search suggestion provider / JavaScript search API, which is public by default. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.7282 (99.4th percentile), indicating substantial predicted exploitation activity. References are limited to the patch, vendor advisory and issue tracker, with no public exploit tag.
What to do
- Upgrade to XWiki 15.6RC1, 15.5.1 or 14.10.15, which fix the issue by not listing documents whose rights cannot be checked.
- If immediate upgrade is not possible, restrict network access to the Solr search suggestion provider and the JavaScript search API to trusted users only.
- Review wiki content for sensitive data that may have been exposed and rotate any credentials or secrets stored in documents.
- Monitor vendor advisory GHSA-7fqr-97j7-jgf4 and XWIKI-21138 for any updated guidance, since no workaround is documented.
Detection
- Audit Solr search API requests for explicit field lists that omit the fields used for rights checking.
- Monitor for unauthenticated or anomalous access to the search suggestion endpoint from unexpected source IPs.
- Review web and application logs for bulk document retrieval patterns consistent with enumerating all wiki content.
- Alert on access to the search API from accounts or networks that do not normally use search functionality.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/xwiki/xwiki-platform/commit/93b8ec702d7075f0f5794bb05dfb651382596764 | Patch |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-7fqr-97j7-jgf4 | Vendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-21138 | Issue TrackingVendor Advisory |
| https://github.com/xwiki/xwiki-platform/commit/93b8ec702d7075f0f5794bb05dfb651382596764 | Patch |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-7fqr-97j7-jgf4 | Vendor Advisory |
| https://jira.xwiki.org/browse/XWIKI-21138 | Issue TrackingVendor Advisory |
Track CVE-2023-48241 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-48241), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.