PT-2024-24333 · Xwiki · Xwiki Platform
Michael Hamann
·
Published
2023-09-21
·
Updated
2025-01-21
·
CVE-2024-31981
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions 3.0.1 through 4.10.19
XWiki Platform versions 14.10.19 and earlier
XWiki Platform versions 15.5.3 and earlier
XWiki Platform versions prior to 15.10-rc-1
Description
XWiki Platform is a generic wiki platform. Remote code execution is possible via PDF export templates. This issue has been patched in XWiki 14.10.20, 15.5.4, and 15.10-rc-1.
Recommendations
For XWiki Platform versions 3.0.1 through 4.10.19, update to version 4.10.20 or later.
For XWiki Platform versions 14.10.19 and earlier, update to version 14.10.20 or later.
For XWiki Platform versions 15.5.3 and earlier, update to version 15.5.4 or later.
For XWiki Platform versions prior to 15.10-rc-1, update to version 15.10-rc-1 or later.
As a temporary workaround, if PDF templates are not typically used on the instance, an administrator can create the document
XWiki.PDFClass and block its edition, after making sure that it does not contain a style attribute.Exploit
Fix
RCE
Missing Authorization
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xwiki Platform