An unauthenticated user can retrieve a list of users and their full names through a publicly accessible URL in XWiki. The issue affects versions before 12.10.11, 13.4.4, and 13.9-rc-1.
id: CVE-2022-24819
info:
name: XWiki < 12.10.11, 13.4.4 & 13.9-rc-1 - Information Disclosure
au
...