XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with version 8.3-rc-1 and prior to versions 12.10.3 and 14.0, one can ask for any file located in the classloader using the template API and a path with ".." in it. The issue is patched in versions 14.0 and 13.10.3. There is no easy workaround for this issue.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6014 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with version 8.3-rc-1 and prior to versions 12.10.3 and 14.0, one can ask for any file located in the classloader using the template API and a path with ".." in it. The issue is patched in versions 14.0 and 13.10.3. There is no easy workaround for this issue. |
Github GHSA |
GHSA-9qrp-h7fw-42hg | Path Traversal in XWiki Platform |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T18:21:49.180Z
Reserved: 2022-04-13T00:00:00.000Z
Link: CVE-2022-29253
Updated: 2024-08-03T06:17:54.535Z
Status : Modified
Published: 2022-05-25T21:15:08.470
Modified: 2024-11-21T06:58:48.807
Link: CVE-2022-29253
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA