PT-2023-20661 · Xwiki · Xwiki Platform

Michael Hamann

·

Published

2023-03-02

·

Updated

2023-03-13

·

CVE-2023-26470

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions XWiki Platform versions prior to 14.0
Description The issue allows an attacker to make the farm unusable by adding an object to a page with a huge number, filling the memory allocated to XWiki and making it unusable every time the document is manipulated.
Recommendations For versions prior to 14.0, update to XWiki 14.0 or later to resolve the issue. As a temporary workaround, consider restricting the ability to add objects to pages to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-26470
GHSA-92WP-R7HM-42G7

Affected Products

Xwiki Platform