Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x2qm-r4wx-8gpg

Опубликовано: 03 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 10

Описание

org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerability

Impact

It's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the newThemeName request parameter (URL parameter), in combination with additional parameters form_token=1&action=create.

For instance: http://127.0.0.1:8080/xwiki/bin/view/FlamingoThemesCode/WebHomeSheet?newThemeName=foo%22%2F%7D%7D%7B%7Basync%20async%3D%22true%22%20cached%3D%22false%22%20context%3D%22doc.reference%22%7D%7D%7B%7Bgroovy%7D%7Dprintln(%22hello%20from%20groovy!%22)%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D&form_token=1&action=create will execute the following groovy code: println("hello from groovy!") on the server.

Patches

This has been patched in the supported versions 13.10.10, 14.9-rc-1, and 14.4.6.

Workarounds

It is possible to edit FlamingoThemesCode.WebHomeSheet and manually perform the changes from the patch fixing the issue.

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.xwiki.platform:xwiki-platform-flamingo-theme-ui

maven
Затронутые версииВерсия исправления

>= 6.2.4, < 13.10.10

13.10.10

Наименование

org.xwiki.platform:xwiki-platform-flamingo-theme-ui

maven
Затронутые версииВерсия исправления

>= 14.0, < 14.4.6

14.4.6

Наименование

org.xwiki.platform:xwiki-platform-flamingo-theme-ui

maven
Затронутые версииВерсия исправления

>= 14.5, < 14.9-rc-1

14.9-rc-1

EPSS

Процентиль: 98%
0.45936
Средний

10 Critical

CVSS3

Дефекты

CWE-94
CWE-95

Связанные уязвимости

CVSS3: 10
nvd
почти 3 года назад

XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the `newThemeName` request parameter (URL parameter), in combination with additional parameters. This has been patched in the supported versions 13.10.10, 14.9-rc-1, and 14.4.6. As a workaround, it is possible to edit `FlamingoThemesCode.WebHomeSheet` and manually perform the changes from the patch fixing the issue.

EPSS

Процентиль: 98%
0.45936
Средний

10 Critical

CVSS3

Дефекты

CWE-94
CWE-95