{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "5.0-milestone-1"
              },
              {
                "fixed": "14.4.8"
              }
            ]
          },
          "events": [
            {
              "introduced": "8f431e0388bc2591ab2122a704a6de9ce1d72fb0"
            },
            {
              "fixed": "b469b950e7fe3d22f00b639d43f286bf871472b1"
            }
          ],
          "repo": "https://github.com/xwiki/xwiki-platform",
          "type": "GIT"
        },
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "14.5"
              },
              {
                "fixed": "14.10.4"
              }
            ]
          },
          "events": [
            {
              "introduced": "ab4dfeaeef13360eebcaa507bc652073aa89a427"
            },
            {
              "fixed": "c127075e7814ef7cd164bb6493d67b1943b6db1e"
            }
          ],
          "repo": "https://github.com/xwiki/xwiki-platform",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-7f2f-pcv3-j2r7"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-200"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34466.json"
  },
  "details": "XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.0-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, tags from pages not viewable to the current user are leaked by the tags API. This information can also be exploited to infer the document reference of non-viewable pages. This vulnerability has been patched in XWiki 14.4.8, 14.10.4, and 15.0-rc-1.\n\n",
  "id": "CVE-2023-34466",
  "modified": "2026-04-01T23:09:39.595201255Z",
  "published": "2023-06-23T15:26:11.453Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://jira.xwiki.org/browse/XWIKI-20002"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34466.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-7f2f-pcv3-j2r7"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34466"
    }
  ],
  "schema_version": "1.7.3",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "XWiki Platform's tags on non-viewable pages can be revealed to users"
}