Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rh28-mqj4-8x59 | XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests |
Mon, 10 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to the `LiveTableResults`, it is still possible to discover password hashes one bit at a time, so with 768 requests, the full password salt and hash can be retrieved of a user. The check for password (and email properties) has been adjusted in XWiki 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17. As a workaround, the patch can be applied manually to the wiki page `XWiki.LiveTableResultsMacros`. | |
| Title | XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests | |
| Weaknesses | CWE-359 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-10T21:11:09.009Z
Reserved: 2026-05-20T18:15:53.578Z
Link: CVE-2026-48048
Updated: 2026-08-10T19:03:22.743Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-10T18:45:17Z
-
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
Github GHSA