QID 982046

QID 982046: Java (maven) Security Update for org.xwiki.commons:xwiki-commons-core (GHSA-h353-hc43-95vc)

Security update has been released for org.xwiki.commons:xwiki-commons-core to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

A user without Script or Programming right is able to execute script requiring privileges by editing gadget titles in the dashboard.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    The issue has been patched in XWiki 12.6.7, 12.10.3 and 13.0RC1.Workaround:
    There's no easy workaround for this issue, it is recommended to upgrade XWiki.
    Vendor References

    CVEs related to QID 982046

    Software Advisories
    Advisory ID Software Component Link
    GHSA-h353-hc43-95vc org.xwiki.commons:xwiki-commons-core URL Logo github.com/advisories/GHSA-h353-hc43-95vc