PT-2025-48545 · Xwiki · Xjetty+1
Published
2025-08-06
·
Updated
2026-03-02
·
CVE-2025-55749
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
XWiki versions 16.7.0 through 16.10.11
XWiki versions 17.4.0 through 17.4.4
XWiki version 17.7.0
Description
XWiki, an open-source wiki software platform, has an issue where the XWiki Jetty package (XJetty) exposes a context allowing static access to any file within the webapp/ folder. This can allow unauthorized access to files potentially containing sensitive information such as credentials. The issue affects instances using the XWiki Jetty package. The vulnerability stems from flaws in the access control mechanism.
Recommendations
XWiki versions 16.7.0 through 16.10.11: Upgrade to version 16.10.11 or later.
XWiki versions 17.4.0 through 17.4.4: Upgrade to version 17.4.4 or later.
XWiki version 17.7.0: Upgrade to a version later than 17.7.0.
As a workaround, modify the
start xwiki.sh script as described at https://github.com/xwiki/xwiki-platform/compare/8b68d8a70b43f25391b3ee48477d7eb71b95cf4b...99a04a0e2143583f5154a43e02174155da7e8e10.Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xjetty
Xwiki