A vulnerability in XWiki Platform's REST API allows unauthorized users to access document history information. The REST API endpoint exposes the history of any page including modification times, version numbers, author details (username and display name), and version comments, regardless of access rights configuration, even on private wikis.
id: CVE-2024-45591
info:
name: XWiki Platform - Unauthorized Document History Access
author: pd
...