PT-2024-36576 · Unknown · Xwiki Platform

Michael Hamann

·

Published

2024-12-12

·

Updated

2024-12-13

·

CVE-2024-55662

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XWiki Platform versions 3.3-milestone-1 through 15.10.8 XWiki Platform versions 3.3-milestone-1 through 16.2.x
Description XWiki Platform is a generic wiki platform. On instances where Extension Repository Application is installed, any user can execute any code requiring programming rights on the server. This issue has been fixed in XWiki 15.10.9 and 16.3.0. Since Extension Repository Application is not mandatory, it can be safely disabled on instances that do not use it as a workaround. It is also possible to manually apply the patches from commit 8659f17d500522bf33595e402391592a35a162e8 to the page ExtensionCode.ExtensionSheet and to the page ExtensionCode.ExtensionAuthorsDisplayer.
Recommendations For XWiki Platform versions 3.3-milestone-1 through 15.10.8, update to version 15.10.9 or later. For XWiki Platform versions 3.3-milestone-1 through 16.2.x, update to version 16.3.0 or later. As a temporary workaround, consider disabling the Extension Repository Application on instances that do not use it. Restrict access to the ExtensionCode.ExtensionSheet and ExtensionCode.ExtensionAuthorsDisplayer pages to minimize the risk of exploitation. Manually apply the patches from commit 8659f17d500522bf33595e402391592a35a162e8 to the page ExtensionCode.ExtensionSheet and to the page ExtensionCode.ExtensionAuthorsDisplayer as an alternative solution.

Exploit

Fix

Code Injection

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-55662
GHSA-J2PQ-22JJ-4PM5

Affected Products

Xwiki Platform