PT-2024-36576 · Unknown · Xwiki Platform
Michael Hamann
·
Published
2024-12-12
·
Updated
2024-12-13
·
CVE-2024-55662
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions 3.3-milestone-1 through 15.10.8
XWiki Platform versions 3.3-milestone-1 through 16.2.x
Description
XWiki Platform is a generic wiki platform. On instances where
Extension Repository Application is installed, any user can execute any code requiring programming rights on the server. This issue has been fixed in XWiki 15.10.9 and 16.3.0. Since Extension Repository Application is not mandatory, it can be safely disabled on instances that do not use it as a workaround. It is also possible to manually apply the patches from commit 8659f17d500522bf33595e402391592a35a162e8 to the page ExtensionCode.ExtensionSheet and to the page ExtensionCode.ExtensionAuthorsDisplayer.Recommendations
For XWiki Platform versions 3.3-milestone-1 through 15.10.8, update to version 15.10.9 or later.
For XWiki Platform versions 3.3-milestone-1 through 16.2.x, update to version 16.3.0 or later.
As a temporary workaround, consider disabling the
Extension Repository Application on instances that do not use it.
Restrict access to the ExtensionCode.ExtensionSheet and ExtensionCode.ExtensionAuthorsDisplayer pages to minimize the risk of exploitation.
Manually apply the patches from commit 8659f17d500522bf33595e402391592a35a162e8 to the page ExtensionCode.ExtensionSheet and to the page ExtensionCode.ExtensionAuthorsDisplayer as an alternative solution.Exploit
Fix
Code Injection
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xwiki Platform