XWiki Platform Vulnerability: Any User Can Execute Code
CVE-2024-55662

10CRITICAL

Key Information:

Vendor
Xwiki
Vendor
CVE Published:
12 December 2024

Summary

The XWiki Platform is a flexible wiki solution that, when utilizing the Extension Repository Application prior to versions 15.10.9 and 16.3.0, exposes the system to a significant vulnerability. Any authenticated user can exploit this flaw to execute arbitrary code on the server, particularly with programming rights. To mitigate this issue, instances not utilizing the Extension Repository Application can disable it as a workaround. For those who require continued use of the application, manual patches can be applied to crucial pages to rectify the vulnerability, following the guidance provided in GitHub commit 8659f17d500522bf33595e402391592a35a162e8.

Affected Version(s)

xwiki-platform >= 3.3-milestone-1, < 15.10.9 < 3.3-milestone-1, 15.10.9

xwiki-platform >= 16.0.0-rc-1, < 16.3.0 < 16.0.0-rc-1, 16.3.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.