PT-2025-54746 · Maven · Org.Xwiki.Platform:Xwiki-Platform-Tool-Jetty-Resources

Publicado

2025-12-01

·

Atualizado

2025-12-01

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Impact

In an instance which is using the XWiki Jetty package (XJetty), a context is exposed to statically access any file located in the webapp/ folder.

Patches

This has been patched in 16.10.11, 17.4.4, 17.7.0.

Workarounds

For more information

If you have any questions or comments about this advisory:

Attribution

Vulnerability reported by Joseph Huber.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-53GX-J3P6-2RW9

Produtos afetados

Org.Xwiki.Platform:Xwiki-Platform-Tool-Jetty-Resources