Количество 3
Количество 3
CVE-2023-36468
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an XWiki installation is upgraded and that upgrade contains a fix for a bug in a document, just a new version of that document is added. In some cases, it's still possible to exploit the vulnerability that was fixed in the new version. The severity of this depends on the fixed vulnerability, for the purpose of this advisory take CVE-2022-36100/GHSA-2g5c-228j-p52x as example - it is easily exploitable with just view rights and critical. When XWiki is upgraded from a version before the fix for it (e.g., 14.3) to a version including the fix (e.g., 14.4), the vulnerability can still be reproduced by adding `rev=1.1` to the URL used in the reproduction steps so remote code execution is possible even after upgrading. Therefore, this affects the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability also affects manually added script macros tha
GHSA-8q9q-r9v2-644m
Upgrading doesn't prevent exploiting vulnerable XWiki documents
BDU:2023-05132
Уязвимость платформы создания совместных веб-приложений XWiki Platform XWiki существует из-за неполной очистки временных или вспомогательных ресурсов, позволяющая нарушителю повысить свои привилегии
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-36468 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an XWiki installation is upgraded and that upgrade contains a fix for a bug in a document, just a new version of that document is added. In some cases, it's still possible to exploit the vulnerability that was fixed in the new version. The severity of this depends on the fixed vulnerability, for the purpose of this advisory take CVE-2022-36100/GHSA-2g5c-228j-p52x as example - it is easily exploitable with just view rights and critical. When XWiki is upgraded from a version before the fix for it (e.g., 14.3) to a version including the fix (e.g., 14.4), the vulnerability can still be reproduced by adding `rev=1.1` to the URL used in the reproduction steps so remote code execution is possible even after upgrading. Therefore, this affects the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability also affects manually added script macros tha | CVSS3: 9.9 | 10% Средний | больше 2 лет назад | |
GHSA-8q9q-r9v2-644m Upgrading doesn't prevent exploiting vulnerable XWiki documents | CVSS3: 9.9 | 10% Средний | больше 2 лет назад | |
BDU:2023-05132 Уязвимость платформы создания совместных веб-приложений XWiki Platform XWiki существует из-за неполной очистки временных или вспомогательных ресурсов, позволяющая нарушителю повысить свои привилегии | CVSS3: 8.8 | 10% Средний | больше 2 лет назад |
Уязвимостей на страницу