Impact
A double‑encoded parent‑directory segment in the /skin/ action of XWiki Platform, when run on Jetty 12 or later, can resolve to files outside of the intended skin or web‑application resource prefix. The vulnerable logic uses Environment.getResourceAsStream(String, String), which limits lookups to resources with the expected prefix but is bypassed by improper path decoding. This enables an unauthenticated remote attacker to read arbitrary resources that the Jetty process can access, such as the WEB‑INF/xwiki.cfg configuration file or, depending on the deployment depth and operating‑system permissions, host files. The vulnerability is a classic directory traversal flaw identified as CWE‑24 and does not require authentication or elevated privileges to exploit.
Affected Systems
XWiki Platform releases prior to 17.10.5 and 18.2.0 are affected when deployed with Jetty 12 or newer. Versions using Tomcat or Jetty before 12 are not impacted. This issue is fixed in XWiki Platform 17.10.5 and 18.2.0 and later releases.
Risk and Exploitability
The CVSS score of 8.2 classifies this vulnerability as high severity. The EPSS score is <1%, indicating a very low but nonzero probability of exploitation. KEV is not listed, so there is no known public exploit at the time of reporting. The vulnerability is easy to trigger over the network by making a crafted request to the /skin/ endpoint, allowing an unauthenticated attacker to read arbitrary resources that the Jetty process can access.
OpenCVE Enrichment
Github GHSA