PT-2025-14787 · Xwiki · Xwiki Jira Extension

Published

2022-11-03

·

Updated

2025-04-04

·

CVE-2025-31487

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions XWiki JIRA extension versions prior to 8.6.5
Description The issue allows any logged-in XWiki user to potentially access and display local files on the XWiki server host by exploiting the JIRA macro. This can be achieved by specifying a fake JIRA URL that returns an XML with a DOCTYPE pointing to a local file, which can then be displayed in certain JIRA fields, such as the summary or description.
Recommendations For versions prior to 8.6.5, update to version 8.6.5 or later to resolve the issue. As a temporary workaround, consider disabling the JIRA macro until a patch is available.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

BDU:2025-03887
CVE-2025-31487
GHSA-WC53-4255-GW3F

Affected Products

Xwiki Jira Extension