PT-2022-16966 · Xwiki · Xwiki
Caleb James Delisle
·
Published
2022-04-28
·
Updated
2023-07-06
·
CVE-2022-24897
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
XWiki versions 2.3 through 12.6.6
XWiki versions 12.7.0 through 12.10.2
XWiki versions 13.0.0 through 13.0.0 before 13.0RC1
Description
The velocity scripts are not properly sandboxed against using the Java File API to perform read or write operations on the filesystem. Writing an attacking script in Velocity requires the Script rights in XWiki, and it also requires finding an XWiki API which returns a File.
Recommendations
For versions 2.3 through 12.6.6, upgrade to version 12.6.7 or later.
For versions 12.7.0 through 12.10.2, upgrade to version 12.10.3 or later.
For versions 13.0.0 through 13.0.0 before 13.0RC1, upgrade to version 13.0RC1 or later.
As a general mitigation measure, be careful when giving Script rights in XWiki.
Exploit
Fix
Path traversal
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xwiki