{"id":"CVE-2024-46978","aliases":["GHSA-r95w-889q-x2gx"],"url":"https://o3.security/vulnerability/CVE-2024-46978","summary":"Missing checks for notification filter preferences editions in XWiki Platform","details":"### Impact\n\nIt's possible for any user knowing the ID of a notification filter preference of another user, to enable/disable it or even delete it. The impact is that the target user might start loosing notifications on some pages because of this.\nThis vulnerability is present in XWiki since 13.2-rc-1. \n\n### Patches\n\nThe vulnerability has been patched in XWiki 14.10.21, 15.5.5, 15.10.1, 16.0-rc-1. The patch consists in checking properly the rights of the user before performing any action on the filters. \n\n### Workarounds\n\nIt's possible to fix manually the vulnerability by editing the document `XWiki.Notifications.Code.NotificationPreferenceService` to apply the changes performed in this commit e8acc9d8e6af7dfbfe70716ded431642ae4a6dd4.\n\n### References\n\n  * JIRA ticket: https://jira.xwiki.org/browse/XWIKI-20337\n  * Commit: e8acc9d8e6af7dfbfe70716ded431642ae4a6dd4\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)\n* Email us at [Security Mailing List](mailto:security@xwiki.org)\n\n### Attribution\n\nThis vulnerability has been reported on Intigriti by @floerer","published":"2024-09-18T17:25:15.821Z","modified":"2026-08-12T03:51:38.881016527Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-notifications-ui","fixedVersion":"14.10.21"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-notifications-ui","fixedVersion":"15.5.5"},{"ecosystem":"Maven","name":"org.xwiki.platform:xwiki-platform-notifications-ui","fixedVersion":"15.10.1"}],"fix":{"url":"https://github.com/xwiki/xwiki-platform/commit/e8acc9d8e6af7dfbfe70716ded431642ae4a6dd4","label":"xwiki/xwiki-platform@e8acc9d"},"references":[{"type":"WEB","url":"https://jira.xwiki.org/browse/XWIKI-20337"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/46xxx/CVE-2024-46978.json"},{"type":"ADVISORY","url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-r95w-889q-x2gx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-46978"},{"type":"FIX","url":"https://github.com/xwiki/xwiki-platform/commit/e8acc9d8e6af7dfbfe70716ded431642ae4a6dd4"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/4771573dac88e0cf04e30f1a8dfa183c048d503a"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/99193a7e9a203b5bb8b2583ac96f5f4d56b9aa1a"},{"type":"WEB","url":"https://github.com/xwiki/xwiki-platform/commit/b9180b874a22e383ad5f2cd9e25bfed4594d4955"},{"type":"PACKAGE","url":"https://github.com/xwiki/xwiki-platform"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:38.881016527Z"}}