XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jjm5-5v9v-7hx2 | org.xwiki.platform:xwiki-platform-security-authentication-default XSS with authenticate endpoints |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 07 Feb 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-06T17:02:00.453Z
Reserved: 2023-04-07T18:56:54.625Z
Link: CVE-2023-29506
Updated: 2024-08-02T14:07:46.433Z
Status : Modified
Published: 2023-04-16T07:15:53.123
Modified: 2024-11-21T07:57:11.703
Link: CVE-2023-29506
No data.
OpenCVE Enrichment
No data.
Github GHSA