Security vulnerabilities in Wiki.js #7733
-
|
Hello @NGPixel, Our team would like to inform you that security vulnerabilities were discovered in Wiki.js. We submitted a report to you on June 11 (https://github.com/requarks/wiki/security/advisories/new), but it's almost 2 months with no response. We also created an issue (#7698), but we haven't received any feedback here either. Please be informed that our team plans to release a technical research, which will include details of the discovered vulnerabilities. Please note, according to our policy, we reserve the right to publicly disclose our findings, if we do not receive a response from you within 90 days. We kindly ask you to review our request and get back to us as soon as possible. Look forward to hearing from you. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 5 replies
-
|
Sorry for the late reply. The 3 vulnerabilities you submitted are known limitations and will be addressed in full in 3.x. The In the meantime, the role description could be changed to clarify these limitations. |
Beta Was this translation helpful? Give feedback.
Sorry for the late reply. The 3 vulnerabilities you submitted are known limitations and will be addressed in full in 3.x. The
manage:usersandmanage:groupsare considered administrator roles and as such, the attack vector is extremely low.In the meantime, the role description could be changed to clarify these limitations.