{"api_version":"1","generated_at":"2026-10-08T08:46:53+00:00","cve":"CVE-2025-58049","urls":{"html":"https://cve.report/CVE-2025-58049","api":"https://cve.report/api/cve/CVE-2025-58049.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-58049","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-58049"},"summary":{"title":"XWiki PDF export jobs store sensitive cookies unencrypted in job statuses","description":"XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, and 17.0.0-rc-1 to before 17.4.0-rc-1, the PDF export jobs store sensitive cookies unencrypted in job statuses. XWiki shouldn't store passwords in plain text, and it shouldn't be possible to gain access to plain text passwords by gaining access to, e.g., a backup of the data directory. This vulnerability has been patched in XWiki 16.4.8, 16.10.7, and 17.4.0-rc-1.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2025-08-28 18:15:33","updated_at":"2026-09-26 00:10:00"},"problem_types":["CWE-212","CWE-257","CWE-212 CWE-212: Improper Removal of Sensitive Information Before Storage or Transfer","CWE-257 CWE-257: Storing Passwords in a Recoverable Format"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"5.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"5.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.8,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://jira.xwiki.org/browse/XWIKI-23151","name":"https://jira.xwiki.org/browse/XWIKI-23151","refsource":"security-advisories@github.com","tags":["Exploit","Issue Tracking","Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/xwiki/xwiki-platform/commit/60982ad0057b1701ed8297f28cad35d170686539","name":"https://github.com/xwiki/xwiki-platform/commit/60982ad0057b1701ed8297f28cad35d170686539","refsource":"security-advisories@github.com","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-9m7c-m33f-3429","name":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-9m7c-m33f-3429","refsource":"security-advisories@github.com","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-58049","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58049","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"xwiki","product":"xwiki-platform","version":"affected >= 14.4.2, < 16.4.8","platforms":[]},{"source":"CNA","vendor":"xwiki","product":"xwiki-platform","version":"affected >= 16.5.0-rc-1, < 16.10.7","platforms":[]},{"source":"CNA","vendor":"xwiki","product":"xwiki-platform","version":"affected >= 17.0.0-rc-1, < 17.4.0-rc-1","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2025","cve_id":"58049","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xwiki","cpe5":"xwiki","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-58049","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2025-08-28T18:15:42.371947Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-08-28T18:15:47.326Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"xwiki-platform","vendor":"xwiki","versions":[{"status":"affected","version":">= 14.4.2, < 16.4.8"},{"status":"affected","version":">= 16.5.0-rc-1, < 16.10.7"},{"status":"affected","version":">= 17.0.0-rc-1, < 17.4.0-rc-1"}]}],"descriptions":[{"lang":"en","value":"XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, and 17.0.0-rc-1 to before 17.4.0-rc-1, the PDF export jobs store sensitive cookies unencrypted in job statuses. XWiki shouldn't store passwords in plain text, and it shouldn't be possible to gain access to plain text passwords by gaining access to, e.g., a backup of the data directory. This vulnerability has been patched in XWiki 16.4.8, 16.10.7, and 17.4.0-rc-1."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.8,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-212","description":"CWE-212: Improper Removal of Sensitive Information Before Storage or Transfer","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-257","description":"CWE-257: Storing Passwords in a Recoverable Format","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-08-28T17:43:39.779Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-9m7c-m33f-3429","tags":["x_refsource_CONFIRM"],"url":"https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-9m7c-m33f-3429"},{"name":"https://github.com/xwiki/xwiki-platform/commit/60982ad0057b1701ed8297f28cad35d170686539","tags":["x_refsource_MISC"],"url":"https://github.com/xwiki/xwiki-platform/commit/60982ad0057b1701ed8297f28cad35d170686539"},{"name":"https://jira.xwiki.org/browse/XWIKI-23151","tags":["x_refsource_MISC"],"url":"https://jira.xwiki.org/browse/XWIKI-23151"}],"source":{"advisory":"GHSA-9m7c-m33f-3429","discovery":"UNKNOWN"},"title":"XWiki PDF export jobs store sensitive cookies unencrypted in job statuses"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2025-58049","datePublished":"2025-08-28T17:43:39.779Z","dateReserved":"2025-08-22T14:30:32.221Z","dateUpdated":"2025-08-28T18:15:47.326Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2025-08-28 18:15:33","lastModifiedDate":"2026-09-26 00:10:00","problem_types":["CWE-212","CWE-257","CWE-212 CWE-212: Improper Removal of Sensitive Information Before Storage or Transfer","CWE-257 CWE-257: Storing Passwords in a Recoverable Format"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-28T18:15:42.371947Z","id":"CVE-2025-58049","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*","versionStartIncluding":"14.4.2","versionEndExcluding":"16.4.8","matchCriteriaId":"532F5636-F862-48B4-BA5F-F0BF391352AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"16.10.7","matchCriteriaId":"6DEAB833-8F14-42C3-9716-BFF595E82F52"},{"vulnerable":true,"criteria":"cpe:2.3:a:xwiki:xwiki:*:*:*:*:*:*:*:*","versionStartIncluding":"17.0.0","versionEndIncluding":"17.3.0","matchCriteriaId":"D1B3E17E-EB52-4E36-9D50-4045914A05F9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"58049","Ordinal":"1","Title":"XWiki PDF export jobs store sensitive cookies unencrypted in job","CVE":"CVE-2025-58049","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"58049","Ordinal":"1","NoteData":"XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, and 17.0.0-rc-1 to before 17.4.0-rc-1, the PDF export jobs store sensitive cookies unencrypted in job statuses. XWiki shouldn't store passwords in plain text, and it shouldn't be possible to gain access to plain text passwords by gaining access to, e.g., a backup of the data directory. This vulnerability has been patched in XWiki 16.4.8, 16.10.7, and 17.4.0-rc-1.","Type":"Description","Title":"XWiki PDF export jobs store sensitive cookies unencrypted in job"}]}}}