JIRA Integration Flaw in XWiki Affects User Profile Access
CVE-2025-31487
7.7HIGH
What is CVE-2025-31487?
The XWiki JIRA extension allows logged-in users to manipulate their user profile pages by utilizing a JIRA macro. If configured with a malicious JIRA URL, this macro can issue requests that expose sensitive files from the XWiki server. This occurs through an XML response that relies on incorrectly parsed DOCTYPE declarations, potentially leading to unauthorized information disclosure. The vulnerability can be mitigated by updating to JIRA Extension version 8.6.5, which provides patching for this exploit.
Affected Version(s)
jira >= 4.2, < 8.5.6