QID 982046
QID 982046: Java (maven) Security Update for org.xwiki.commons:xwiki-commons-core (GHSA-h353-hc43-95vc)
Security update has been released for org.xwiki.commons:xwiki-commons-core to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A user without Script or Programming right is able to execute script requiring privileges by editing gadget titles in the dashboard.
Solution
The issue has been patched in XWiki 12.6.7, 12.10.3 and 13.0RC1.Workaround:
There's no easy workaround for this issue, it is recommended to upgrade XWiki.
There's no easy workaround for this issue, it is recommended to upgrade XWiki.
Vendor References
- GHSA-h353-hc43-95vc -
github.com/advisories/GHSA-h353-hc43-95vc
CVEs related to QID 982046
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h353-hc43-95vc | org.xwiki.commons:xwiki-commons-core |
|