Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9jq5-xwqw-q8j3

Опубликовано: 20 апр. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

XWiki Platform vulnerable to page render failure due to broken translations

Impact

It's possible to break many translations coming from wiki pages by creating a corrupted document containing a translation object.

Patches

The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11.

Workarounds

There is no other workaround other than fixing any way to create a document that fail to load.

References

https://jira.xwiki.org/browse/XWIKI-20460

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-localization-source-wiki

maven
Затронутые версииВерсия исправления

>= 4.3-milestone-2, < 13.10.11

13.10.11

Наименование

org.xwiki.platform:xwiki-platform-localization-source-wiki

maven
Затронутые версииВерсия исправления

>= 14.0-rc-1, < 14.4.8

14.4.8

Наименование

org.xwiki.platform:xwiki-platform-localization-source-wiki

maven
Затронутые версииВерсия исправления

>= 14.5, < 14.10.1

14.10.1

EPSS

Процентиль: 44%
0.00213
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-248
CWE-755

Связанные уязвимости

CVSS3: 4.3
nvd
почти 3 года назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to break many translations coming from wiki pages by creating a corrupted document containing a translation object. This will lead to a broken page. The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11. Users are advised to upgrade. There are no workarounds other than fixing any way to create a document that fail to load.

EPSS

Процентиль: 44%
0.00213
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-248
CWE-755