CVE-2023-29506
Summary
| CVE | CVE-2023-29506 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-16 07:15:00 UTC |
| Updated | 2023-04-26 17:45:00 UTC |
| Description | XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| RXSS with authenticate endpoints · Advisory · xwiki/xwiki-platform · GitHub | MISC | github.com | |
| Loading... | MISC | jira.xwiki.org | |
| XWIKI-20335: Wiki existence is not properly checked in authenticate · xwiki/xwiki-platform@1943ea2 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.