Published:2020/07/28  Last Updated:2020/07/28

JVN#48194211
Multiple vulnerabilities in KonaWiki2 and KonaWiki3

Overview

KonaWiki2 and KonaWiki3 contain multiple vulnerabilities.

Products Affected

  • KonaWiki2.2.0 and earlier
  • KonaWiki3.1.0 and earlier

Description

KonaWiki2 and KonaWiki3 are lightweight wiki clones that support Japanese wiki notation. KonaWiki2 and KonaWiki3 contain multiple vulnerabilities listed below.

KonaWiki2

  • Cross-site Scripting (CWE-79) - CVE-2020-5612
    CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Base Score: 6.1
    CVSS v2 AV:N/AC:M/Au:N/C:N/I:P/A:N Base Score: 4.3
KonaWiki3
  • Cross-site Scripting (CWE-79) - CVE-2020-5613
    CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Base Score: 6.1
    CVSS v2 AV:N/AC:M/Au:N/C:N/I:P/A:N Base Score: 4.3
  • Path Traversal (CWE-22) - CVE-2020-5614
    CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score: 5.3
    CVSS v2 AV:N/AC:L/Au:N/C:P/I:N/A:N Base Score: 5.0

Impact

  • Because the sanitizing process is not performed properly, an arbitrary web script is executed on the web browser of the user who accesses a specially crafted URL. - CVE-2020-5612, CVE-2020-5613
  • Inadequate query checking allows unauthorized disclosure of information stored above the target directory published as a site by a remote attacker. - CVE-2020-5614

Solution

Update the software
Update the software to the latest version according to the information provided by the developer.

  • KonaWiki2.2.1
  • KonaWiki3.1.1

Vendor Status

Vendor Status Last Update Vendor Notes
kujirahand Vulnerable 2020/07/28 kujirahand website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Satoki Tsuji reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2020-5612
CVE-2020-5613
CVE-2020-5614
JVN iPedia JVNDB-2020-000048