PT-2025-48545 · Xwiki · Xjetty+1

Published

2025-08-06

·

Updated

2026-03-02

·

CVE-2025-55749

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions XWiki versions 16.7.0 through 16.10.11 XWiki versions 17.4.0 through 17.4.4 XWiki version 17.7.0
Description XWiki, an open-source wiki software platform, has an issue where the XWiki Jetty package (XJetty) exposes a context allowing static access to any file within the webapp/ folder. This can allow unauthorized access to files potentially containing sensitive information such as credentials. The issue affects instances using the XWiki Jetty package. The vulnerability stems from flaws in the access control mechanism.
Recommendations XWiki versions 16.7.0 through 16.10.11: Upgrade to version 16.10.11 or later. XWiki versions 17.4.0 through 17.4.4: Upgrade to version 17.4.4 or later. XWiki version 17.7.0: Upgrade to a version later than 17.7.0. As a workaround, modify the start xwiki.sh script as described at https://github.com/xwiki/xwiki-platform/compare/8b68d8a70b43f25391b3ee48477d7eb71b95cf4b...99a04a0e2143583f5154a43e02174155da7e8e10.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-15017
CVE-2025-55749
GHSA-53GX-J3P6-2RW9

Affected Products

Xjetty
Xwiki