CVE Vulnerabilities

CVE-2023-27480

Improper Restriction of XML External Entity Reference

Published: Mar 07, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.7
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit rights on a document can trigger an XAR import on a forged XAR file, leading to the ability to display the content of any file on the XWiki server host. This vulnerability has been patched in XWiki 13.10.11, 14.4.7 and 14.10-rc-1. Users are advised to upgrade. Users unable to upgrade may apply the patch e3527b98fd manually.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

Name Vendor Start Version End Version
Xwiki Xwiki 1.1 (excluding) 13.10.11 (excluding)
Xwiki Xwiki 14.0 (including) 14.4.7 (excluding)
Xwiki Xwiki 14.5 (including) 14.10 (excluding)
Xwiki Xwiki 1.1-milestone3 (including) 1.1-milestone3 (including)
Xwiki Xwiki 1.1-milestone4 (including) 1.1-milestone4 (including)

Potential Mitigations

References