PT-2024-36576 · Unknown · Xwiki Platform
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
XWiki Platform versions 3.3-milestone-1 through 15.10.8
XWiki Platform versions 3.3-milestone-1 through 16.2.x
Description
XWiki Platform is a generic wiki platform. On instances where
Extension Repository Application is installed, any user can execute any code requiring programming rights on the server. This issue has been fixed in XWiki 15.10.9 and 16.3.0. Since Extension Repository Application is not mandatory, it can be safely disabled on instances that do not use it as a workaround. It is also possible to manually apply the patches from commit 8659f17d500522bf33595e402391592a35a162e8 to the page ExtensionCode.ExtensionSheet and to the page ExtensionCode.ExtensionAuthorsDisplayer.Recommendations
For XWiki Platform versions 3.3-milestone-1 through 15.10.8, update to version 15.10.9 or later.
For XWiki Platform versions 3.3-milestone-1 through 16.2.x, update to version 16.3.0 or later.
As a temporary workaround, consider disabling the
Extension Repository Application on instances that do not use it.
Restrict access to the ExtensionCode.ExtensionSheet and ExtensionCode.ExtensionAuthorsDisplayer pages to minimize the risk of exploitation.
Manually apply the patches from commit 8659f17d500522bf33595e402391592a35a162e8 to the page ExtensionCode.ExtensionSheet and to the page ExtensionCode.ExtensionAuthorsDisplayer as an alternative solution.Exploit
Fix
DoS
Incorrect Authorization
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xwiki Platform