XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with version 8.3-rc-1 and prior to versions 12.10.3 and 14.0, one can ask for any file located in the classloader using the template API and a path with ".." in it. The issue is patched in versions 14.0 and 13.10.3. There is no easy workaround for this issue.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-05-25T20:55:10

Updated: 2024-08-03T06:17:54.535Z

Reserved: 2022-04-13T00:00:00

Link: CVE-2022-29253

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-05-25T21:15:08.470

Modified: 2022-06-07T19:48:48.287

Link: CVE-2022-29253

cve-icon Redhat

No data.