PT-2025-54746 · Maven · Org.Xwiki.Platform:Xwiki-Platform-Tool-Jetty-Resources

Published

2025-12-01

·

Updated

2025-12-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Impact

In an instance which is using the XWiki Jetty package (XJetty), a context is exposed to statically access any file located in the webapp/ folder.

Patches

This has been patched in 16.10.11, 17.4.4, 17.7.0.

Workarounds

For more information

If you have any questions or comments about this advisory:

Attribution

Vulnerability reported by Joseph Huber.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-53GX-J3P6-2RW9

Affected Products

Org.Xwiki.Platform:Xwiki-Platform-Tool-Jetty-Resources