Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2r87-74cx-2p7c

Опубликовано: 12 дек. 2024
Источник: github
Github: Прошло ревью
CVSS3: 9.9

Описание

XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList

Impact

Any user with an account can perform arbitrary remote code execution by adding instances of XWiki.WikiMacroClass to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation.

To reproduce on a instance, as a connected user without script nor programming rights, go to your user profile and add an object of type XWiki.WikiMacroClass. Set "Macro Id", "Macro Name" and "Macro Code" to any value, "Macro Visibility" to Current User and "Macro Description" to {{async}}{{groovy}}println("Hello from User macro!"){{/groovy}}{{/async}}. Save the page, then go to <host>/xwiki/bin/view/XWiki/XWikiSyntaxMacrosList. If the description of your new macro reads "Hello from User macro!", then your instance is vulnerable.

Patches

This vulnerability has been fixed in XWiki 15.10.11, 16.4.1 and 16.5.0.

Workarounds

It is possible to manually apply this patch to the page XWiki.XWikiSyntaxMacrosList.

References

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-help-ui

maven
Затронутые версииВерсия исправления

>= 9.7-rc-1, < 15.10.11

15.10.11

Наименование

org.xwiki.platform:xwiki-platform-help-ui

maven
Затронутые версииВерсия исправления

>= 16.0.0-rc-1, < 16.4.1

16.4.1

Наименование

org.xwiki.platform:xwiki-platform-help-ui

maven
Затронутые версииВерсия исправления

>= 16.5.0-rc-1, < 16.5.0

16.5.0

EPSS

Процентиль: 97%
0.39407
Средний

9.9 Critical

CVSS3

Дефекты

CWE-94
CWE-96

Связанные уязвимости

CVSS3: 9.9
nvd
около 1 года назад

XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can perform arbitrary remote code execution by adding instances of `XWiki.WikiMacroClass` to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been fixed in XWiki 15.10.11, 16.4.1 and 16.5.0. It is possible to manually apply the patch to the page `XWiki.XWikiSyntaxMacrosList` as a workaround.

EPSS

Процентиль: 97%
0.39407
Средний

9.9 Critical

CVSS3

Дефекты

CWE-94
CWE-96