PT-2023-20661 · Xwiki · Xwiki Platform

Michael Hamann

·

Publicado

2023-03-02

·

Atualizado

2023-03-13

·

CVE-2023-26470

CVSS v3.1

5.7

Média

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions XWiki Platform versions prior to 14.0
Description The issue allows an attacker to make the farm unusable by adding an object to a page with a huge number, filling the memory allocated to XWiki and making it unusable every time the document is manipulated.
Recommendations For versions prior to 14.0, update to XWiki 14.0 or later to resolve the issue. As a temporary workaround, consider restricting the ability to add objects to pages to minimize the risk of exploitation.

Exploit

Correção

DoS

Resource Exhaustion

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-26470
GHSA-92WP-R7HM-42G7

Produtos afetados

Xwiki Platform